Vulnerability record · CVE-2018-8006 · published 10 October 2018
CVE-2018-8006: Apache ActiveMQ admin console queue.jsp reflected XSS via QueueFilter
Apache · Activemq
Apache ActiveMQ versions 5.0.0 through 5.15.5 contain a reflected cross-site scripting flaw in the web administration console's queue.jsp page. The QueueFilter parameter is not properly filtered before being returned to the browser, allowing script injection into the admin console page. Because the console is used to manage brokers and queues, a successful attack can compromise an administrator's session.
Description
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw is a reflected XSS requiring user interaction and only affects the admin console, but it targets privileged users and has a high EPSS score.
What it is
Apache ActiveMQ versions 5.0.0 through 5.15.5 contain a reflected cross-site scripting flaw in the web administration console's queue.jsp page. The QueueFilter parameter is not properly filtered before being returned to the browser, allowing script injection into the admin console page. Because the console is used to manage brokers and queues, a successful attack can compromise an administrator's session.
Impact
An attacker can execute arbitrary script in the context of an authenticated ActiveMQ administrator's browser, potentially stealing session cookies or performing administrative actions as that user. The CVSS vector shows scope change with low confidentiality and integrity impact, and no availability impact.
Attack surface
Reached over the network through the web-based administration console at queue.jsp, with the malicious payload carried in the QueueFilter parameter. The CVSS vector requires user interaction (UI:R) and no privileges (PR:N), meaning the victim administrator must be induced to load a crafted link or page.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.57227, 99th percentile), but the reference tags only include vendor and third-party advisories, with no public exploit or PoC tags.
What to do
- Upgrade Apache ActiveMQ to a version later than 5.15.5 that contains the fix for CVE-2018-8006.
- If immediate upgrade is not possible, restrict network access to the ActiveMQ web administration console to trusted management networks only.
- Require administrators to access the console over a trusted path and avoid clicking untrusted links that point to queue.jsp.
- Apply input validation or a reverse-proxy/WAF rule that blocks script payloads in the QueueFilter parameter.
- Review ActiveMQ security advisories for any additional hardening guidance tied to this issue.
Detection
- Search web server or proxy logs for requests to queue.jsp containing suspicious characters or script tags in the QueueFilter parameter.
- Monitor for reflected script content in responses from the ActiveMQ admin console, especially where QueueFilter is echoed back.
- Alert on administrator sessions that originate from unusual referrers or that follow links containing encoded script payloads.
- Review ActiveMQ admin console access logs for unexpected or anomalous queue.jsp requests from external or untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-8006 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8006), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.