Apache Software Foundation Apache Activemq Artemis vulnerabilities

8 known vulnerabilities affecting apache_software_foundation/apache_activemq_artemis.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM2LOW2

Vulnerabilities

Page 1 of 1
CVE-2026-32642LOWCVSS 2.3≥ 2.0.0, ≤ 2.44.02026-03-24
CVE-2026-32642 [LOW] CWE-863 CVE-2026-32642: Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists wh Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permissi
cvelistv5nvd
CVE-2026-27446CRITICALCVSS 9.3≥ 2.11.0, ≤ 2.44.02026-03-04
CVE-2026-27446 [CRITICAL] CWE-306 Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This c
cvelistv5
CVE-2025-27391MEDIUMCVSS 6.8≥ 1.5.1, < 2.40.02025-04-09
CVE-2025-27391 [MEDIUM] CWE-532 CVE-2025-27391: Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the v Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restric
cvelistv5nvd
CVE-2025-27427LOWCVSS 2.3≥ 2.0.0, ≤ 2.39.02025-04-01
CVE-2025-27427 [LOW] CWE-863 CVE-2025-27427: A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or crea A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation
cvelistv5nvd
CVE-2023-50780HIGHCVSS 8.8fixed in 2.29.02024-10-14
CVE-2023-50780 [HIGH] CWE-285 CVE-2023-50780: Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which a Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an authenticated attacker to write arbi
cvelistv5nvd
CVE-2022-35278MEDIUMCVSS 6.1≥ unspecified, ≤ 2.23.12022-08-23
CVE-2022-35278 [MEDIUM] CWE-80 CVE-2022-35278: In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
cvelistv5nvd
CVE-2022-23913HIGHCVSS 7.5≥ 2.19.0, < 2.20.02022-02-04
CVE-2022-23913 [HIGH] CWE-770 CVE-2022-23913: In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availabili In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.
cvelistv5nvd
CVE-2021-26118HIGHCVSS 7.5≥ unspecified, < 2.16.02021-01-27
CVE-2021-26118 [HIGH] CWE-284 CVE-2021-26118: While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.
cvelistv5nvd