Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.activemq:activemq-client(Maven) | 5.0.0 | 5.11.3 | N/A |
| org.apache.activemq:activemq-client(Maven) | 5.12.0 | 5.12.2 | N/A |
CVSS Metrics