Описание
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | not-affected | 5.17.6+dfsg-1 |
| esm-apps/bionic | released | 5.15.8-2~18.04.1~esm1 |
| esm-apps/focal | released | 5.15.11-1ubuntu0.1~esm1 |
| esm-apps/jammy | not-affected | 5.16.1-1 |
| esm-apps/noble | not-affected | 5.17.6+dfsg-1 |
| esm-apps/xenial | released | 5.13.2+dfsg-2ubuntu0.1~esm1 |
| esm-infra-legacy/trusty | DNE | |
| focal | ignored | end of standard support, was needed |
| groovy | ignored | end of life |
Показывать по
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
The optional ActiveMQ LDAP login module can be configured to use anony ...
Improper Authentication in Apache ActiveMQ and Apache Artemis
5 Medium
CVSS2
7.5 High
CVSS3