Security Advisory

CVE-2018-11775

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-09-10 20:00:00
Last updated 2024-09-16 16:23:47
Assigner apache
CVSS score not scored
State PUBLISHED

Description

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.