Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cpw7-g3p5-qrfq

Опубликовано: 01 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Apache ActiveMQ server has an incomplete authorization workflow

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.

This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.

Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.

Пакеты

Наименование

org.apache.activemq:apache-activemq

maven
Затронутые версииВерсия исправления

< 5.19.7

5.19.7

Наименование

org.apache.activemq:apache-activemq

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.2.6

6.2.6

EPSS

Процентиль: 27%
0.00348
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.

CVSS3: 6.5
redhat
2 месяца назад

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.

CVSS3: 4.3
nvd
2 месяца назад

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.

CVSS3: 4.3
debian
2 месяца назад

Incomplete authorization by Apache ActiveMQ server before versions v6. ...

CVSS3: 4.3
redos
11 дней назад

Уязвимость apache-activemq

EPSS

Процентиль: 27%
0.00348
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-285