activemq-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Atholl Stewart (JIRA)" <>
Subject [jira] [Created] (AMQ-5414) stored XSS via MQ message
Date Tue, 28 Oct 2014 15:36:34 GMT
Atholl Stewart created AMQ-5414:

             Summary:  stored XSS via MQ message
                 Key: AMQ-5414
             Project: ActiveMQ
          Issue Type: Bug
          Components: webconsole
    Affects Versions: 5.10.0
            Reporter: Atholl Stewart

When a MQ message is received containing a maliciously crafted payload via STOMP, AMQP etc.
then a stored XSS is created when the message is viewed in the management interface. 

This message was sent by Atlassian JIRA

View raw message