org.apache.activemq:activemq-fileserver@5.4.3 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.activemq:activemq-fileserver package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Improper Input Validation

org.apache.activemq:activemq-fileserver is an open source messaging and Integration Patterns server.

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

[5.0.0,5.13.3)
  • M
Directory Traversal

org.apache.activemq:activemq-fileserver is a web File Server for out of band large message exchange.

Affected versions of this package are vulnerable to Directory Traversal in the fileserver upload/download functionality for blob messages. It allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.

How to fix Directory Traversal?

Upgrade org.apache.activemq:activemq-fileserver to version 5.11.2 or higher.

[5.0.0,5.11.2)