cbcvebase.
CVE-2022-41678
published 2023-11-28

CVE-2022-41678: Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ configurations, jetty allows…

PriorityP180high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
85.81%
99.7th percentile
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest is able to create JmxRequest through JSONObject. And calls to org.jolokia.http.HttpRequestHandler#executeRequest. Into deeper calling stacks, org.jolokia.handler.ExecHandler#doHandleRequest can be invoked through refection. This could lead to RCE through via various mbeans. One example is unrestricted deserialization in jdk.management.jfr.FlightRecorderMXBeanImpl which exists on Java version above 11. 1 Call newRecording. 2 Call setConfiguration. And a webshell data hides in it. 3 Call startRecording. 4 Call copyTo method. The webshell will be written to a .jsp file. The mitigation is to restrict (by default) the actions authorized on Jolokia, or disable Jolokia. A more restrictive Jolokia configuration has been defined in default ActiveMQ distribution. We encourage users to upgrade to ActiveMQ distributions version including updated Jolokia configuration: 5.16.6, 5.17.4, 5.18.0, 6.0.0.

Affected

13 ranges
VendorProductVersion rangeFixed in
apacheactivemq< 5.16.65.16.6
apacheactivemq>= 0 < 5.16.1-1+deb11u15.16.1-1+deb11u1
apacheactivemq>= 0 < 5.17.2+dfsg-2+deb12u15.17.2+dfsg-2+deb12u1
apacheactivemq>= 0 < 5.17.6+dfsg-15.17.6+dfsg-1
apacheactivemq>= 0 < 5.16.1-1ubuntu0.15.16.1-1ubuntu0.1
apacheactivemq>= 0 < 5.13.2+dfsg-2ubuntu0.1~esm15.13.2+dfsg-2ubuntu0.1~esm1
apacheactivemq>= 0 < 5.15.8-2~18.04.1~esm15.15.8-2~18.04.1~esm1
apacheactivemq>= 0 < 5.15.11-1ubuntu0.1~esm15.15.11-1ubuntu0.1~esm1
apacheactivemq>= 0 < 5.16.1-1ubuntu0.1~esm15.16.1-1ubuntu0.1~esm1
apacheactivemq>= 5.17.0 < 5.17.45.17.4
apache_software_foundationapache_activemq< 5.16.65.16.6
apache_software_foundationapache_activemq>= 5.17.0 < 5.17.45.17.4
debianactivemq< activemq 5.17.2+dfsg-2+deb12u1 (bookworm)activemq 5.17.2+dfsg-2+deb12u1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

url/api/jolokia
url/api/jolokia/list/org.apache.logging.log4j2
filename*.jsp
  • Detect POST requests to /api/jolokia — the exploit uses HttpRequestHandler#handlePostRequest to create JmxRequest via JSONObject for RCE
  • Alert on Jolokia exec-handler invocations targeting jdk.management.jfr.FlightRecorderMXBeanImpl — specifically the sequence: newRecording → setConfiguration (with embedded webshell) → startRecording → copyTo
  • Monitor for the four-step exploit chain: (1) newRecording, (2) setConfiguration with embedded payload, (3) startRecording, (4) copyTo writing a .jsp webshell to disk
  • Use Shodan/FOFA queries to identify exposed ActiveMQ instances as potential targets: shodan 'http.title:"ActiveMQ"', fofa 'title="ActiveMQ"'
  • Detect GET requests to /api/jolokia/list/org.apache.logging.log4j2 with Basic auth header — used by PoC to probe for vulnerable setConfigText/getConfigText operations
  • Response body containing both 'setConfigText' and 'getConfigText' from /api/jolokia indicates a vulnerable ActiveMQ instance
  • CVE-2026-34197 is a bypass for CVE-2022-41678; on ActiveMQ versions 6.0.0–6.1.1, CVE-2024-32114 exposes the Jolokia API without authentication, making this effectively unauthenticated RCE
  • Default credentials admin:admin (Base64: YWRtaW46YWRtaW4=) are commonly used in exploitation; flag any Jolokia authentication using these credentials
  • ·Exploitation requires authenticated access to Jolokia; environments with strong authentication and properly restricted or disabled Jolokia are at significantly reduced risk
  • ·The FlightRecorderMXBeanImpl deserialization vector only applies to Java 11 and above; Java versions below 11 are not affected by this specific exploitation path
  • ·On ActiveMQ 6.0.0–6.1.1, CVE-2024-32114 removes the authentication requirement entirely, elevating this to unauthenticated RCE when chained

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.