Re: CVE-2024-22243 Spring Framework Open Redirect Vulnerability - ActiveMQ 5.3.30

2024-03-07 Thread Matthew Gay
g version. > > 5.3.30 is the Spring version, used in ActiveMQ 5.18.x. ActiveMQ 5.18.4 > will upgrade to Spring 5.3.31 fixing the CVE. > > Regards > JB > > On Thu, Mar 7, 2024 at 2:25 PM Matthew Gay > wrote: > > > > Good Morning, > > > > We are receiving sca

CVE-2024-22243 Spring Framework Open Redirect Vulnerability - ActiveMQ 5.3.30

2024-03-07 Thread Matthew Gay
Good Morning, We are receiving scan reports regarding ActiveMQ being vulnerable to the above CVE. We have seen a couple emails that allude to ActiveMQ not being vulnerable. However, we are looking for a more official response indicating if it is, or is not vulnerable. And to add - when an