CVE-2025-27427
published 2025-04-01CVE-2025-27427: A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the…
PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.58%
43.8th percentile
A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address.
This issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.0.
Users are recommended to upgrade to version 2.40.0 which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | artemis | >= 2.0.0 < 2.40.0 | 2.40.0 |
| apache_software_foundation | apache_activemq_artemis | 2.0.0 – 2.39.0 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
osv·2025-04-01
CVE-2025-27427 [LOW] Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address.
This issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.0.
Users are recommended to upgrade to version 2.
GHSA
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
ghsa·2025-04-01
CVE-2025-27427 [LOW] CWE-863 Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address.
This issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.0.
Users are recommended to upgrade to version 2.
Red Hat
org.apache.activemq/artemis-core-client: Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permission
vendor_redhat·2025-04-01·CVSS 2.3
CVE-2025-27427 [LOW] CWE-863 org.apache.activemq/artemis-core-client: Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permission
org.apache.activemq/artemis-core-client: Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permission
A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address.
This issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.
No detection rules found.
No public exploits indexed.
2025-04-01
Published