Apache ActiveMQ Artemis vulnerable to Improper Access Control
High severity
GitHub Reviewed
Published
Jun 16, 2021
to the GitHub Advisory Database
•
Updated Sep 11, 2023
Package
Affected versions
< 2.16.0
Patched versions
2.16.0
Description
Published by the National Vulnerability Database
Jan 27, 2021
Reviewed
Apr 5, 2021
Published to the GitHub Advisory Database
Jun 16, 2021
Last updated
Sep 11, 2023
While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.
References