Impact
A remote attacker who has not yet authenticated can exploit the CORE protocol by sending a SUBSCRIBE_TOPOLOGY of the cluster topology including node identities. This information disclosure (CWE‑306) can aid attackers in mapping the environment, facilitating further targeted attacks.
Affected Systems
Apache Software Foundation’s Apache Artemis is vulnerable in versions 2.50.0 through 2.56.0. Apache ActiveMQ Artemis is affected from 1.0.0 through 2.44.0. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The vulnerability requires only an unauthenticated network connection The CVSS score of 7.5 indicates a high severity assessment. The EPSS score of < 1% indicates a very low exploitation probability, and the flaw is not listed in CISA KEV. The potential for pre‑authentication data leakage is significant. Attackers could use the disclosed topology information to identify high‑value nodes or plan further intrusions. The impact is primarily confidentiality loss of cluster configuration information.
OpenCVE Enrichment