<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:51:32 +0000</lastBuildDate>
    <item>
      <title>BIT-activemq-2020-13920</title>
      <link>https://cve.radiocsirt.org/vuln/bit-activemq-2020-13920</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the &amp;#34;jmxrmi&amp;#34; entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the &amp;#34;jmxrmi&amp;#34; entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-activemq-2020-13920</guid>
    </item>
    <item>
      <title>cnvd-2020-51793</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-51793</link>
      <description>cnvd-2020-51793</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-51793</guid>
    </item>
    <item>
      <title>EUVD-2026-42091</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42091</link>
      <description>EUVD-2026-42091</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42091</guid>
    </item>
    <item>
      <title>fkie_cve-2020-13920</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13920</link>
      <description>&lt;p&gt;Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the &amp;#34;jmxrmi&amp;#34; entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the &amp;#34;jmxrmi&amp;#34; entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-13920</guid>
    </item>
    <item>
      <title>GHSA-xgrx-xpv2-6vp4 — Improper Authentication in Apache ActiveMQ</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xgrx-xpv2-6vp4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:activemq-parent&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the &amp;#34;jmxrmi&amp;#34; entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:activemq-parent&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the &amp;#34;jmxrmi&amp;#34; entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xgrx-xpv2-6vp4</guid>
    </item>
    <item>
      <title>gsd-2020-13920</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-13920</link>
      <description>gsd-2020-13920</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-13920</guid>
    </item>
    <item>
      <title>RHSA-2021:3140 — Red Hat Security Advisory: Red Hat Fuse 7.9.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3140</link>
      <description>&lt;p&gt;log4j: Socket receiver deserialization vulnerability snakeyaml: Billion laughs attack via alias feature apache-commons-compress: Infinite loop in name encoding algorithm wildfly: The &amp;#39;enabled-protocols&amp;#39; value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class olingo-odata: Server side request forgery in AsyncResponseWrapperImpl tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability spring-cloud-config-server: sending a request using a specially crafted URL can lead to a directory traversal attack springframework: RFD protection bypass via jsessionid Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 tomcat: deserialization flaw in session persistence storage leading to RCE RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack hibernate-validator: Improper input validation in the interpolation of constraint error messages wildfly-elytron: session fixation when using FORM authentication undertow: invalid HTTP request with large chunk size tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;log4j: Socket receiver deserialization vulnerability snakeyaml: Billion laughs attack via alias feature apache-commons-compress: Infinite loop in name encoding algorithm wildfly: The &amp;#39;enabled-protocols&amp;#39; value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class olingo-odata: Server side request forgery in AsyncResponseWrapperImpl tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability spring-cloud-config-server: sending a request using a specially crafted URL can lead to a directory traversal attack springframework: RFD protection bypass via jsessionid Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 tomcat: deserialization flaw in session persistence storage leading to RCE RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack hibernate-validator: Improper input validation in the interpolation of constraint error messages wildfly-elytron: session fixation when using FORM authentication undertow: invalid HTTP request with large chunk size tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3140</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-13920</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13920</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the &amp;#34;jmxrmi&amp;#34; entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the &amp;#34;jmxrmi&amp;#34; entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13920</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2970 — Apache ActiveMQ: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2970</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache ActiveMQ ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache ActiveMQ ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2970</guid>
    </item>
  </channel>
</rss>
