Description
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2583-1 | activemq security update |
Debian DLA |
DLA-3657-1 | activemq security update |
Github GHSA |
GHSA-9mgm-gcq8-86wq | Improper Authentication in Apache ActiveMQ and Apache Artemis |
Ubuntu USN |
USN-6910-1 | Apache ActiveMQ vulnerabilities |
References
History
No history.
Subscriptions
Apache
Subscribe
Activemq
Subscribe
Activemq Artemis
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Netapp
Subscribe
Oncommand Workflow Automation
Subscribe
Oracle
Subscribe
Communications Element Manager
Subscribe
Communications Session Report Manager
Subscribe
Communications Session Route Manager
Subscribe
Flexcube Private Banking
Subscribe
Redhat
Subscribe
Amq Broker
Subscribe
Jboss Amq
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T20:19:20.050Z
Reserved: 2021-01-25T00:00:00.000Z
Link: CVE-2021-26117
No data.
Status : Modified
Published: 2021-01-27T19:15:13.720
Modified: 2024-11-21T05:55:53.820
Link: CVE-2021-26117
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Github GHSA
Ubuntu USN