Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q7fr-vqhq-v5xr

Опубликовано: 16 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache ActiveMQ Artemis vulnerable to Improper Access Control

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

Пакеты

Наименование

org.apache.activemq:artemis-openwire-protocol

maven
Затронутые версииВерсия исправления

< 2.16.0

2.16.0

EPSS

Процентиль: 77%
0.0101
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
CWE-287

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

CVSS3: 7.5
redhat
больше 5 лет назад

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

CVSS3: 7.5
nvd
около 5 лет назад

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

EPSS

Процентиль: 77%
0.0101
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
CWE-287