Impact
An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet, taking advantage of a missing authentication check. By sending this packet the attacker hijacks an existing broker session, instantly assuming all privileges that the original authenticated user possessed. This results in a complete session takeover and the potential for arbitrary command execution within the messaging environment.
Affected Systems
The flaw impacts Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0. These are the Apache Artemis messaging broker and the Apache ActiveMQ Artemis broker, so any deployment with those releases that listens for CORE protocol connections is vulnerable.
Risk and Exploitability
The CVSS base score of 9.8 reflects a severe risk due to the high impact and broad scope of the vulnerability. The EPSS score of < 1% indicates that active exploitation is unlikely at present, and the issue is not yet in CISA’s KEV catalog. Nonetheless, because the attacker gains the same rights as the original session owner, a successful exploit would provide full control over the broker and its tenants, making mitigation a high priority.
OpenCVE Enrichment