Описание
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
A flaw was found in Apache ActiveMQ. An unauthenticated attacker can exploit this vulnerability when brokers are configured with a network connector with syncDurableSubs set to true. By sending a BrokerInfo command, the attacker can receive a list of all durable topic subscriptions, including sensitive details like client identifiers, subscription names, topic destinations, and JMS selector expressions. This information disclosure is due to the broker incorrectly responding without first ensuring the connection is authenticated.
Отчет
Red Hat products ship Apache ActiveMQ Classic components as transitive dependencies. The vulnerability allows unauthenticated information disclosure via BrokerInfo commands when the broker has a network connector with syncDurableSubs=true configured. This is a non-default configuration specific to Classic ActiveMQ broker-to-broker networking. Red Hat AMQ Broker is based on Apache ActiveMQ Artemis, which handles BrokerInfo commands through its own code and does not use Classic's network connector configuration. The vulnerable code path is not exercised in Red Hat product deployments.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | activemq-artemis-native | Fix deferred | ||
| Red Hat AMQ Broker 7 | activemq-client | Fix deferred | ||
| Red Hat AMQ Broker 7 | activemq-openwire-legacy | Fix deferred | ||
| Red Hat AMQ Broker 7 | apache-artemis | Fix deferred | ||
| Red Hat AMQ Broker 7 | artemis-amqp-protocol | Fix deferred | ||
| Red Hat AMQ Broker 7 | artemis-boot | Fix deferred | ||
| Red Hat AMQ Broker 7 | artemis-cli | Fix deferred | ||
| Red Hat AMQ Broker 7 | artemis-commons | Fix deferred | ||
| Red Hat AMQ Broker 7 | artemis-console | Fix deferred | ||
| Red Hat AMQ Broker 7 | artemis-console-war | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
Exposure of Sensitive Information Through Metadata vulnerability in Ap ...
Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability
EPSS
7.5 High
CVSS3