The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2583-1 | activemq security update |
Debian DLA |
DLA-3657-1 | activemq security update |
Github GHSA |
GHSA-9mgm-gcq8-86wq | Improper Authentication in Apache ActiveMQ and Apache Artemis |
Ubuntu USN |
USN-6910-1 | Apache ActiveMQ vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T20:19:20.050Z
Reserved: 2021-01-25T00:00:00
Link: CVE-2021-26117
No data.
Status : Modified
Published: 2021-01-27T19:15:13.720
Modified: 2024-11-21T05:55:53.820
Link: CVE-2021-26117
OpenCVE Enrichment
No data.
Debian DLA
Github GHSA
Ubuntu USN