Description
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security manager. In other words, a rogue remote client could make your Java application execute arbitrary code." Mitigation: Upgrade to Apache ActiveMQ 5.15.13
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1236 | A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security manager. In other words, a rogue remote client could make your Java application execute arbitrary code." Mitigation: Upgrade to Apache ActiveMQ 5.15.13 |
Github GHSA |
GHSA-wqfh-9m4g-7x6x | Remote code execution in Apache ActiveMQ |
References
History
No history.
Subscriptions
Apache
Subscribe
Activemq
Subscribe
Oracle
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Element Manager
Subscribe
Communications Session Report Manager
Subscribe
Communications Session Route Manager
Subscribe
Enterprise Repository
Subscribe
Flexcube Private Banking
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T11:48:57.796Z
Reserved: 2020-04-21T00:00:00.000Z
Link: CVE-2020-11998
No data.
Status : Modified
Published: 2020-09-10T19:15:13.083
Modified: 2024-11-21T04:59:05.040
Link: CVE-2020-11998
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA