Summary
ActiveMQ 5.19.x requires Java 11+; the 32 catalogued CVEs are pinned at the latest Java 1.8 line. Mitigation: in-VM broker only, empty , simpleAuthenticationPlugin with anonymousAccessAllowed=false, per-queue constantPendingMessageLimit=1000. Closing PRs: #167 (issue #166), #211, #213, #215, #217.
Mitigation matrix
See docs/SECURITY-MITIGATIONS.md T2.2 entry for the per-GAV mitigation table.
OWASP suppressions
Per-CVE entries with notes describing the mitigation are in owasp-suppressions.xml.
Closing evidence
References
Summary
ActiveMQ 5.19.x requires Java 11+; the 32 catalogued CVEs are pinned at the latest Java 1.8 line. Mitigation: in-VM broker only, empty , simpleAuthenticationPlugin with anonymousAccessAllowed=false, per-queue constantPendingMessageLimit=1000. Closing PRs: #167 (issue #166), #211, #213, #215, #217.
Mitigation matrix
See
docs/SECURITY-MITIGATIONS.mdT2.2 entry for the per-GAV mitigation table.OWASP suppressions
Per-CVE entries with notes describing the mitigation are in
owasp-suppressions.xml.Closing evidence
docs/SECURITY-MITIGATIONS.mdT2.2 entryowasp-suppressions.xmlReferences