Apache

Activemq Artemis

12 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Published 09.04.2025 15:16:02
  • Last modified 14.07.2025 12:12:22

Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. ...

  • EPSS 0.17%
  • Published 01.04.2025 08:15:13
  • Last modified 14.07.2025 12:08:45

A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress per...

  • EPSS 0.25%
  • Published 14.10.2024 16:15:03
  • Last modified 19.03.2025 21:15:35

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for ex...

  • EPSS 4.24%
  • Published 24.08.2022 16:15:09
  • Last modified 21.11.2024 06:36:46

A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attac...

  • EPSS 1.27%
  • Published 23.08.2022 15:15:11
  • Last modified 21.11.2024 07:11:01

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

Exploit
  • EPSS 0.16%
  • Published 04.02.2022 23:15:15
  • Last modified 21.11.2024 06:49:27

In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.

  • EPSS 16.3%
  • Published 27.01.2021 19:15:13
  • Last modified 21.11.2024 05:55:53

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is...

  • EPSS 1.01%
  • Published 27.01.2021 19:15:13
  • Last modified 21.11.2024 05:55:54

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not ...

  • EPSS 2.55%
  • Published 20.07.2020 22:15:11
  • Last modified 21.11.2024 05:02:10

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is tri...

  • EPSS 0.08%
  • Published 26.06.2020 16:15:12
  • Last modified 21.11.2024 04:55:56

A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation....