Package
apache-activemq-fips-6.1
Component
activemq-mqtt
Latest update
5.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
No remedy to this vulnerability exists for this version stream. Remediation would require upstream backporting the fix.
Status
Status
Fixed version
6.2.5-r0Status
Impact
activemq-mqtt and activemq-all at version 6.1.8 contain a vulnerability (GHSA-c825-6ph3-4h84) that the advisory claims is fixed in 6.1.9. However, 6.1.9 was never released: the apache/activemq tag list goes 6.1.8 -> 6.2.0 with no intermediate 6.1.x release. These are primary artifacts of upstream Apache ActiveMQ 6.1.8 built from source in this package and cannot be substituted via dependency overrides. Resolution requires:
Status