14 lines
1.0 KiB
JSON
14 lines
1.0 KiB
JSON
{
|
||
"id": "openEuler-SA-2023-1778",
|
||
"url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2023-1778",
|
||
"title": "An update for activemq is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP3,openEuler-22.03-LTS,openEuler-22.03-LTS-SP1 and openEuler-22.03-LTS-SP2",
|
||
"severity": "Critical",
|
||
"description": "The most popular and powerful open source messaging and Integration Patterns server.\r\n\r\nSecurity Fix(es):\r\n\r\nApache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. \r\n\r\nUsers are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.(CVE-2023-46604)",
|
||
"cves": [
|
||
{
|
||
"id": "CVE-2023-46604",
|
||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46604",
|
||
"severity": "Critical"
|
||
}
|
||
]
|
||
} |