Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32642

Опубликовано: 24 мар. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permission and address auto-creation is disabled. In this circumstance, a temporary address will be created whereas the attempt to create the non-durable subscription should instead fail since the user is not authorized to create the corresponding address. When the OpenWire connection is closed the address is removed. This issue affects Apache Artemis: from 2.50.0 through 2.52.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0. Users are recommended to upgrade to version 2.53.0, which fixes the issue.

A flaw was found in Apache Artemis and Apache ActiveMQ Artemis. An authenticated user can exploit this incorrect authorization vulnerability by attempting to create a non-durable Java Message Service (JMS) topic subscription on an address that does not exist. If the user has "createDurableQueue" permission but lacks "createAddress" permission, and address auto-creation is disabled, a temporary address will be unexpectedly created. This bypasses intended authorization, allowing for unauthorized resource creation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Clientsartemis-serverAffected
Red Hat build of Apache Camel for Spring Boot 4artemis-serverAffected
Red Hat build of OptaPlanner 8artemis-serverAffected
Red Hat Fuse 7artemis-serverAffected
Red Hat JBoss Enterprise Application Platform 7artemis-serverAffected
Red Hat JBoss Enterprise Application Platform 8artemis-serverAffected
Red Hat JBoss Enterprise Application Platform Expansion Packartemis-serverAffected
Red Hat Process Automation 7artemis-serverAffected
Red Hat Satellite 6candlepinAffected
Red Hat Satellite 6satellite:el8/candlepinAffected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2450642Apache Artemis: Apache ActiveMQ Artemis: Apache Artemis and Apache ActiveMQ Artemis: Unauthorized address creation due to incorrect authorization during JMS topic subscription.

EPSS

Процентиль: 35%
0.00422
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
5 месяцев назад

Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permission and address auto-creation is disabled. In this circumstance, a temporary address will be created whereas the attempt to create the non-durable subscription should instead fail since the user is not authorized to create the corresponding address. When the OpenWire connection is closed the address is removed. This issue affects Apache Artemis: from 2.50.0 through 2.52.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0. Users are recommended to upgrade to version 2.53.0, which fixes the issue.

CVSS3: 4.3
nvd
5 месяцев назад

Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permission and address auto-creation is disabled. In this circumstance, a temporary address will be created whereas the attempt to create the non-durable subscription should instead fail since the user is not authorized to create the corresponding address. When the OpenWire connection is closed the address is removed. This issue affects Apache Artemis: from 2.50.0 through 2.52.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0. Users are recommended to upgrade to version 2.53.0, which fixes the issue.

github
5 месяцев назад

Apache Artemis: Unauthorized Temporary Address Creation via OpenWire Protocol

EPSS

Процентиль: 35%
0.00422
Низкий

4.3 Medium

CVSS3