CVE Vulnerabilities

CVE-2021-26118

Published: Jan 27, 2021 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

Affected Software

Name Vendor Start Version End Version
Activemq_artemis Apache 2.15.0 (including) 2.15.0 (including)
Red Hat AMQ RedHat *
Red Hat AMQ 7.8.1 RedHat *
Activemq Ubuntu bionic *
Activemq Ubuntu groovy *
Activemq Ubuntu hirsute *
Activemq Ubuntu impish *
Activemq Ubuntu kinetic *
Activemq Ubuntu trusty *
Activemq Ubuntu upstream *
Activemq Ubuntu xenial *

References