QID 981417

QID 981417: Java (maven) Security Update for org.apache.activemq:apache-artemis (GHSA-q7fr-vqhq-v5xr)

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-q7fr-vqhq-v5xr for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981417

    Software Advisories
    Advisory ID Software Component Link
    GHSA-q7fr-vqhq-v5xr org.apache.activemq:apache-artemis URL Logo github.com/advisories/GHSA-q7fr-vqhq-v5xr