Impact
Apache ActiveMQ Artemis before version 2.34.0 contains an unsafe reflection vulnerability in the FederationMessage handling code. The framework directly loads and instantiates a class specified by a federation peer in a FEDERATION_DOWNSTREAM_CONNECT packet. An attacker who can authenticate as a federation peer can send a crafted packet that causes the broker to load an arbitrary class from the Artemis classloader. The class’s static initializer or no‑argument constructor executes as a side effect, allowing the attacker to poison system properties, trigger out‑of‑memory conditions, or otherwise manipulate broker state, which can lead to denial of service or remote code execution.
Affected Systems
Red Hat AMQ Broker 7 and Red Hat JBoss Enterprise Application Platform 7 are affected. All releases that embed Apache ActiveMQ Artemis prior to version 2.34.0 are vulnerable because the unsafe reflection code path remains present.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2 and is not listed in the CISA KEV catalog. The EPSS score is not available, but the exploitability requires the attacker to be an authenticated federation peer, which is typically limited to trusted systems. If the attacker succeeds, they can cause denial of service, manipulate broker state, or potentially execute code through arbitrary class loading. The risk is considered high for environments that allow federation peers from untrusted sources.
OpenCVE Enrichment