CVE Vulnerabilities

CVE-2022-41678

Improper Authentication

Published: Nov 28, 2023 | Modified: Nov 03, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. 

In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia

org.jolokia.http.HttpRequestHandler#handlePostRequest is able to create JmxRequest through JSONObject. And calls to org.jolokia.http.HttpRequestHandler#executeRequest.

Into deeper calling stacks, org.jolokia.handler.ExecHandler#doHandleRequest can be invoked through refection. This could lead to RCE through via various mbeans. One example is unrestricted deserialization in jdk.management.jfr.FlightRecorderMXBeanImpl which exists on Java version above 11.

1 Call newRecording.

2 Call setConfiguration. And a webshell data hides in it.

3 Call startRecording.

4 Call copyTo method. The webshell will be written to a .jsp file.

The mitigation is to restrict (by default) the actions authorized on Jolokia, or disable Jolokia. A more restrictive Jolokia configuration has been defined in default ActiveMQ distribution. We encourage users to upgrade to ActiveMQ distributions version including updated Jolokia configuration: 5.16.6, 5.17.4, 5.18.0, 6.0.0.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
ActivemqApache*5.16.6 (excluding)
ActivemqApache5.17.0 (including)5.17.4 (excluding)
Red Hat AMQ Broker 7RedHat*
Red Hat Fuse 7.13.0RedHatactivemq*
RHEL-8 based Middleware ContainersRedHatamq7/amq-broker-init-rhel8:7.12.0-7*
RHEL-8 based Middleware ContainersRedHatamq7/amq-broker-rhel8:7.12.0-7*
RHEL-8 based Middleware ContainersRedHatamq7/amq-broker-rhel8-operator-bundle:7.12.0-10*
ActivemqUbuntubionic*
ActivemqUbuntuesm-apps/bionic*
ActivemqUbuntuesm-apps/focal*
ActivemqUbuntuesm-apps/jammy*
ActivemqUbuntuesm-apps/xenial*
ActivemqUbuntufocal*
ActivemqUbuntujammy*
ActivemqUbuntulunar*
ActivemqUbuntumantic*
ActivemqUbuntutrusty*
ActivemqUbuntuupstream*
ActivemqUbuntuxenial*

Potential Mitigations

References