Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9vv-xj4w-g8m8

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Apache ActiveMQ Artemis RCE Via Deserialization Gadget Chain

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

Ссылки

Пакеты

Наименование

org.apache.activemq:artemis-pom

maven
Затронутые версииВерсия исправления

< 1.4.0

1.4.0

EPSS

Процентиль: 77%
0.01084
Низкий

7.2 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 6.6
redhat
больше 9 лет назад

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

CVSS3: 7.2
nvd
больше 9 лет назад

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

EPSS

Процентиль: 77%
0.01084
Низкий

7.2 High

CVSS3

Дефекты

CWE-502