Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue
| Vendor | Product | Versions |
|---|---|---|
| apache | activemq | 0, 6.0.0, 0, 6.0.0, 0, 6.0.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apache | activemq_broker | cve_cpe | 95% |
| maven | org.apache.activemq:activemq-broker | GHSA | 85% |
| maven | org.apache.activemq:activemq-all | GHSA | 85% |
Updated description with more technical details and added a new IOC for the exploit.
Updated description with new exploit details and changed severity to HIGH.
Updated severity to HIGH, added information about over 6,400 vulnerable IP addresses, and included new tag CISA KEV.
Updated severity to HIGH and added CVE-2024-32114 as a related vulnerability.
Updated severity to HIGH, added CWE-287, and included CVE-2024-32114 as a related vulnerability.
Added CISA KEV tag and confirmed CVSS score as 8.8.
Updated description with more technical details and added affected version 6.1.1.
Updated description with more technical details and added affected version 6.1.1.
Updated severity from NONE to HIGH and marked the vulnerability as actively exploited.
Updated description with new technical details, changed severity to HIGH, confirmed CVSS score of 8.8, added new CWE ID, marked as actively exploited, and included new IoCs and tags.
Updated description with new technical details, changed severity to HIGH, added new CWEs, and included new IoCs and MITRE ATT&CK technique T1203.
Initial creation