Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99qx-5qqr-4j95

Опубликовано: 01 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Apache ActiveMQ has an Incorrect Default Permissions vulnerability

Incorrect Default Permissions vulnerability in Apache ActiveMQ.

This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.

The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.

Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

Пакеты

Наименование

org.apache.activemq:apache-activemq

maven
Затронутые версииВерсия исправления

< 5.19.7

5.19.7

Наименование

org.apache.activemq:apache-activemq

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.2.6

6.2.6

EPSS

Процентиль: 36%
0.0044
Низкий

8.8 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 8.8
ubuntu
2 месяца назад

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

CVSS3: 8.1
redhat
2 месяца назад

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

CVSS3: 8.8
nvd
2 месяца назад

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

CVSS3: 8.8
debian
2 месяца назад

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This ...

EPSS

Процентиль: 36%
0.0044
Низкий

8.8 High

CVSS3

Дефекты

CWE-276