CVE-2010-1244
Cross-site request forgery in Apache ActiveMQ
EPSS 0.44%
Description
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
How to fix CVE-2010-1244
To remediate CVE-2010-1244, upgrade the affected package to a fixed version below.
- Maven/org.apache.activemq:activemq-parent—upgrade to 5.3.1 or later
Is CVE-2010-1244 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 5.3.1