In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/mosaic-hgw/WildFly
- https://github.com/srchen1987/springcloud-distributed-transaction