cbcvebase.
CVE-2023-50780
published 2024-10-14

CVE-2023-50780: Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint…

PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
16.54%
96.6th percentile
Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an authenticated attacker to write arbitrary files to the filesystem and indirectly achieve RCE. Users are recommended to upgrade to version 2.29.0 or later, which fixes the issue.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheartemis< 2.29.02.29.0
apache_software_foundationapache_activemq_artemis< 2.29.02.29.0

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor authenticated access to the Jolokia endpoint for invocation of the Log4J2 MBean, which should not be accessible to non-administrative users
  • Alert on any authenticated attacker activity via the Jolokia endpoint that results in arbitrary file writes to the filesystem, as this is the exploitation path toward RCE
  • Focus detection on Red Hat JBoss Enterprise Application Platform Expansion Pack deployments, which are confirmed affected; other Red Hat product packages are not affected
  • ·The Log4J2 MBean exposure via the Jolokia endpoint is the vulnerable configuration; upgrading to Apache ActiveMQ Artemis version 2.29.0 or later removes this exposure
  • ·Exploitation requires prior authentication to the Jolokia endpoint, limiting exposure to scenarios involving compromised credentials or insider threats
  • ·No mitigation short of patching is available; Red Hat Product Security found no available options meeting their criteria

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.