Severity
7.5HIGH
EPSS
1.0%
top 22.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateJun 16

Description

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

4
OSV
Apache ActiveMQ Artemis vulnerable to Improper Access Control2021-06-16
GHSA
Apache ActiveMQ Artemis vulnerable to Improper Access Control2021-06-16
OSV
CVE-2021-26118: While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 22021-01-27
CVEList
Flaw in ActiveMQ Artemis OpenWire support2021-01-27

📋Vendor Advisories

1
Red Hat
7: OpenWire can create destinations with an unpriviledged user2020-10-28

💬Community

1
Bugzilla
CVE-2021-26118 AMQ Broker 7: OpenWire can create destinations with an unpriviledged user2020-10-28
CVE-2021-26118 (HIGH CVSS 7.5) | While investigating ARTEMIS-2964 it | cvebase.io