The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.activemq:apache-activemq(Maven) | 0 | 5.8.0 | N/A |
| org.apache.activemq:activemq-web-demo(Maven) | 0 | 5.8.0 | N/A |
CVSS Metrics