GHSA-wqfh-9m4g-7x6x

    Dashboard / Vulnerabilities / GHSA-wqfh-9m4g-7x6x

    GHSA-wqfh-9m4g-7x6x

    Published: 9 Feb 2022Last Modified: 14 Mar 2024

    Summary: Remote code execution in Apache ActiveMQ

    Details: A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack - A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security manager. In other words, a rogue remote client could make your Java application execute arbitrary code. Mitigation - Upgrade to Apache ActiveMQ 5.15.13

    Affected packages

    Package

    Name: org.apache.activemq:activemq-parent

    Purl: pkg:maven/org.apache.activemq/activemq-parent

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 5.15.12
    Fixed -5.15.13

    Affected versions

    5.15.12

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-wqfh-9m4g-7x6x | CVE-DB