Impact
The flaw is an input validation weakness (CWE‑20) in ActiveMQ’s TopicRegion module that lets an authenticated client disguise its clientId when sending a RemoveSubscription command for a durable topic subscription. By spoiling the identifier, an attacker can delete a subscription belonging to another user, thereby causing that user to lose guaranteed message delivery. This does not provide code execution or elevate privileges; it simply alters subscription state and can disrupt service for other tenants.
Affected Systems
Apache ActiveMQ deployments that use the Broker, the bundled All distribution, or the standalone product are affected when running versions older than 5.19.11 or any 6.x release before 6.3.2. Any instance in those release ranges that accepts authenticated connections is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.5 reflects a moderate‑to‑high risk, requiring only valid credentials and the ability to issue a RemoveSubscription request. The EPSS score of less than 1% indicates that exploitation is unlikely to be widespread, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, an attacker who can authenticate can unobtrusively delete other users’ durable subscriptions, which can be a denial‑of‑service or privacy concern in multi‑tenant environments.
OpenCVE Enrichment