Skip to content
artemisGHSA-9mgm-gcq8-86wq

Improper Authentication in Apache ActiveMQ and Apache Artemis

High7.5CVE-2021-26117 · Published Jun 16, 2021 · updated Mar 14, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.activemq:apache-artemis
Maven
< 2.16.02.16.0
Details and references

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287
Also known as
BIT-activemq-2021-26117, CVE-2021-26117

More artemis advisories

All
DateAdvisory
Feb 92022Cross-site Scripting (XSS) in Apache ActiveMQ Artemis
CVE-2020-13932Medium6.1fixed in 2.14.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.