Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mgm-gcq8-86wq

Опубликовано: 16 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Authentication in Apache ActiveMQ and Apache Artemis

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

Ссылки

Пакеты

Наименование

org.apache.activemq:activemq-parent

maven
Затронутые версииВерсия исправления

>= 5.16.0, < 5.16.1

5.16.1

Наименование

org.apache.activemq:activemq-parent

maven
Затронутые версииВерсия исправления

< 5.15.14

5.15.14

Наименование

org.apache.activemq:apache-artemis

maven
Затронутые версииВерсия исправления

< 2.16.0

2.16.0

EPSS

Процентиль: 95%
0.163
Средний

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

CVSS3: 8.1
redhat
больше 5 лет назад

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

CVSS3: 7.5
nvd
около 5 лет назад

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

CVSS3: 7.5
debian
около 5 лет назад

The optional ActiveMQ LDAP login module can be configured to use anony ...

EPSS

Процентиль: 95%
0.163
Средний

7.5 High

CVSS3

Дефекты

CWE-287