VulnerabilityModified
CVE-2010-1244
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a…
MEDIUM 6.8EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- apache/activemq
- Source
- cve@mitre.org
References
- http://activemq.apache.org/activemq-531-release.htmlPatch
- http://secunia.com/advisories/39223Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57398
- https://issues.apache.org/activemq/browse/AMQ-2613Exploit
- https://issues.apache.org/activemq/browse/AMQ-2625Exploit
- http://activemq.apache.org/activemq-531-release.htmlPatch
- http://secunia.com/advisories/39223Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57398
- https://issues.apache.org/activemq/browse/AMQ-2613Exploit
- https://issues.apache.org/activemq/browse/AMQ-2625Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.