GHSA-443j-grxv-2pgv

Suggest an improvement
Source
https://github.com/advisories/GHSA-443j-grxv-2pgv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-443j-grxv-2pgv/GHSA-443j-grxv-2pgv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-443j-grxv-2pgv
Aliases
Published
2024-10-14T18:30:25Z
Modified
2024-10-16T17:33:51.509359Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans
Details

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an authenticated attacker to write arbitrary files to the filesystem and indirectly achieve RCE.

Users are recommended to upgrade to version 2.29.0 or later, which fixes the issue.

Database specific
{
    "nvd_published_at": "2024-10-14T16:15:03Z",
    "cwe_ids": [
        "CWE-285"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-10-14T21:17:11Z"
}
References

Affected packages

Maven / org.apache.activemq:artemis-cli

Package

Name
org.apache.activemq:artemis-cli
View open source insights on deps.dev
Purl
pkg:maven/org.apache.activemq/artemis-cli

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.29.0

Affected versions

1.*

1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6

2.*

2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.7.0
2.8.0
2.8.1
2.9.0
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.20.0
2.21.0
2.22.0
2.23.0
2.23.1
2.24.0
2.25.0
2.26.0
2.27.0
2.27.1
2.28.0