PT-2026-53840 · Apache · Activemq
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ versions prior to 5.19.8
Apache ActiveMQ versions 6.0.0 through 6.2.6
Description
An improper authorization issue exists where an authenticated user with low privileges can access the
/admin/* endpoints in the Web Console. This occurs because the default Jetty settings fail to restrict these paths exclusively to administrators.Recommendations
Upgrade to version 5.19.8.
Upgrade to version 6.2.7.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Activemq