GHSA-r9vv-xj4w-g8m8

    Dashboard / Vulnerabilities / GHSA-r9vv-xj4w-g8m8

    GHSA-r9vv-xj4w-g8m8

    Published: 13 May 2022Last Modified: 13 Mar 2024
    Aliases:

    Summary: Apache ActiveMQ Artemis RCE Via Deserialization Gadget Chain

    Details: The getObject method of the `javax.jms.ObjectMessage` class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

    References: https://nvd.nist.gov/vuln/detail/CVE-2016-4978, https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities.pdf, https://web.archive.org/web/20210123172653/http://www.securityfocus.com/bid/93142, https://lists.apache.org/thread.html/rc96ad63f148f784c84ea7f0a178c84a8985c6afccabbcd9847a82088@%3Ccommits.activemq.apache.org%3E, https://lists.apache.org/thread.html/rc96ad63f148f784c84ea7f0a178c84a8985c6afccabbcd9847a82088%40%3Ccommits.activemq.apache.org%3E, https://lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d@%3Ccommits.activemq.apache.org%3E, https://lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d%40%3Ccommits.activemq.apache.org%3E, https://lists.apache.org/thread.html/d4ffbc6a43a915324a394b2913ceb7d07bc352f2d08caa19df0aff02@%3Cissues.activemq.apache.org%3E, https://lists.apache.org/thread.html/d4ffbc6a43a915324a394b2913ceb7d07bc352f2d08caa19df0aff02%40%3Cissues.activemq.apache.org%3E, https://lists.apache.org/thread.html/7260bd0955c12aac5bd892039d3356ba3aa0ff4caaf2aa4fd4fe84a2@%3Cissues.activemq.apache.org%3E, https://lists.apache.org/thread.html/7260bd0955c12aac5bd892039d3356ba3aa0ff4caaf2aa4fd4fe84a2%40%3Cissues.activemq.apache.org%3E, https://github.com/apache/activemq-artemis, https://access.redhat.com/errata/RHSA-2018:1451, https://access.redhat.com/errata/RHSA-2018:1450, https://access.redhat.com/errata/RHSA-2018:1449, https://access.redhat.com/errata/RHSA-2018:1448, https://access.redhat.com/errata/RHSA-2018:1447, https://access.redhat.com/errata/RHSA-2017:3458, https://access.redhat.com/errata/RHSA-2017:3456, https://access.redhat.com/errata/RHSA-2017:3455, https://access.redhat.com/errata/RHSA-2017:3454, https://access.redhat.com/errata/RHSA-2017:1837, https://access.redhat.com/errata/RHSA-2017:1836, https://access.redhat.com/errata/RHSA-2017:1835, https://access.redhat.com/errata/RHSA-2017:1834, http://mail-archives.apache.org/mod_mbox/activemq-users/201609.mbox/%3CCAH6wpnqzeNtpykT7emtDU1-GV7AvjFP5-YroWcCC4UZyQEFvtA%40mail.gmail.com%3E

    Affected packages

    Package

    Name: org.apache.activemq:artemis-pom

    Purl: pkg:maven/org.apache.activemq/artemis-pom

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.4.0

    Affected versions

    1.0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High