Medium severity6.1NVD Advisory· Published May 14, 2020· Updated Jun 17, 2026
CVE-2020-1941
CVE-2020-1941
Description
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.activemq:activemq-web-consoleMaven | >= 5.0.0, < 5.15.12 | 5.15.12 |
Affected products
17- cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*Range: >=8.0.0,<=8.2.2
cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_report_manager:8.2.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_route_manager:8.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:enterprise_repository:11.1.1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
- Apache/ActiveMQdescription
- osv-coords2 versions
>= 5.0.0, <= 5.15.11+ 1 more
- (no CPE)range: >= 5.0.0, <= 5.15.11
- (no CPE)range: >= 5.0.0, < 5.15.12
Patches
Vulnerability mechanics
References
18- activemq.apache.org/security-advisories.data/CVE-2020-1941-announcement.txtnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-cc94-3v9c-7rm8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-1941ghsaADVISORY
- www.oracle.com//security-alerts/cpujul2021.htmlnvdThird Party Advisory
- www.oracle.com/security-alerts/cpuApr2021.htmlnvdThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujul2020.htmlnvdThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2020.htmlnvdThird Party AdvisoryWEB
- github.com/apache/activemq/commit/7793a95ghsaWEB
- github.com/apache/activemq/commit/81bd743eaa243f0cc5dfbb1342cee1fef1fc5df2ghsaWEB
- github.com/apache/activemq/commit/c0e17a3ghsaWEB
- issues.apache.org/jira/browse/AMQ-7231ghsaWEB
- lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7@%3Ccommits.activemq.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d@%3Ccommits.activemq.apache.org%3EghsaWEB
- lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a@%3Ccommits.activemq.apache.org%3EghsaWEB
- www.oracle.com/security-alerts/cpujul2021.htmlghsaWEB
- lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3Envd
- lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d%40%3Ccommits.activemq.apache.org%3Envd
- lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a%40%3Ccommits.activemq.apache.org%3Envd
News mentions
0No linked articles in our index yet.