IoT & Hardware

Cross-Site Scripting (XSS)

Apache Artemis - XSS Over MQTT

Stored XSS in Apache Artemis In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability.

6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS38
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-13932
VENDORS
Apache
PUBLIC EXPLOIT
None indexed
CWE
CWE-79
PRODUCT
ActiveMQ Artemis 2.5.0-2.13.0
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Stored XSS in Apache Artemis

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console’s browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.

Vulnerability details

Vulnerability details

CVE-2020-13932
CWE-79
Medium | 6.1

Stored XSS in Apache Artemis In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console’s browser.

Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2020-05-20 reported to the vendor 20 July 2020 coordinated public release of advisory

Credits

Arun Magesh