GHSA-43x2-g84q-fmqx

Suggest an improvement
Source
https://github.com/advisories/GHSA-43x2-g84q-fmqx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-43x2-g84q-fmqx/GHSA-43x2-g84q-fmqx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-43x2-g84q-fmqx
Aliases
Published
2026-06-22T21:10:31Z
Modified
2026-06-22T21:26:31Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI
Details

Summary

Description

A Deserialization of Untrusted Data (CWE-502) issue in OpenDJ's JMX RMI connector allows an unauthenticated remote attacker to deserialize arbitrary Java objects on the server. The vulnerability exists because the platform reads and processes attacker-controlled bytes prior to authentication. This affects OpenDJ Community Edition through 5.1.0. This has been patched in version 5.1.1.

Impact

This impacts all current OpenDJ releases where the JMX Connection Handler is enabled. While disabled by default, it is frequently enabled in practice for monitoring integrations. Exploitation requires TCP reachability to the configured listener and does not require authentication, prior privileges, or client certificates. Successful exploitation results in unauthenticated Remote Code Execution (RCE), with the severity depending on the runtime classpath and Java version. Unauthenticated RCE was demonstrated on the OpenDJ 4.4.15 (JDK 11 + Jackson 2.12.6.1).

Patch

This has been patched in OpenDJ Community Edition version 5.1.1. Users are encouraged to update to the latest release.

Database specific
{
    "cwe_ids":  [
        "CWE-502"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-22T21:10:31Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

Maven / org.openidentityplatform.opendj:opendj-server-legacy

Package

Name
org.openidentityplatform.opendj:opendj-server-legacy
View open source insights on deps.dev
Purl
pkg:maven/org.openidentityplatform.opendj/opendj-server-legacy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.1.1

Affected versions

4.*
4.4.7
4.4.8
4.4.9
4.4.10
4.4.11
4.4.12
4.4.13
4.4.14
4.4.15
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.0
4.8.1
4.8.2
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
4.10.0
4.10.1
4.10.2
5.*
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0

Database specific

last_known_affected_version_range
"<= 5.1.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-43x2-g84q-fmqx/GHSA-43x2-g84q-fmqx.json"