Impact
A remote attacker can send a crafted Openwire RemoveSubscriptionInfo command that causes an Artemis broker to delete a queue before the connection is authenticated or at any time thereafter. The flaw is a missing authentication weakness (CWE-306) that allows an attacker to remove a queue from the broker’s configuration, preventing messages from being delivered to that destination.
Affected Systems
The vulnerability affects Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0, all provided by the Apache Software Foundation.
Risk and Exploitability
The impact is a high CVSS score of 9.1, indicating a severe security flaw. The EPSS score is below 1%, indicating a low current exploitation probability, and the issue is not listed in CISA KEV. Based on the description, it is inferred that any client that can reach the Openwire port before authentication may cause a queue to be deleted, so the risk depends on the broker’s exposure to untrusted hosts. In environments where the broker is reachable by external clients, the risk is moderate to high.
OpenCVE Enrichment