Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hf52-78x8-6w3w

Опубликовано: 01 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.

Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.

This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.

Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

Пакеты

Наименование

org.apache.activemq:apache-activemq

maven
Затронутые версииВерсия исправления

< 5.19.7

5.19.7

Наименование

org.apache.activemq:apache-activemq

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.2.6

6.2.6

Наименование

org.apache.activemq:activemq-broker

maven
Затронутые версииВерсия исправления

< 5.19.7

5.19.7

Наименование

org.apache.activemq:activemq-broker

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.2.6

6.2.6

Наименование

org.apache.activemq:activemq-all

maven
Затронутые версииВерсия исправления

< 5.19.7

5.19.7

Наименование

org.apache.activemq:activemq-all

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.2.6

6.2.6

EPSS

Процентиль: 30%
0.00369
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-1230

Связанные уязвимости

CVSS3: 5.9
ubuntu
2 месяца назад

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

CVSS3: 7.5
redhat
2 месяца назад

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

CVSS3: 5.9
nvd
2 месяца назад

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

CVSS3: 5.9
debian
2 месяца назад

Exposure of Sensitive Information Through Metadata vulnerability in Ap ...

CVSS3: 5.9
redos
11 дней назад

Уязвимость apache-activemq

EPSS

Процентиль: 30%
0.00369
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-1230