Bug 2252185 (CVE-2022-41678)
| Summary: | CVE-2022-41678 ActiveMQ: Deserialization vulnerability on Jolokia that allows authenticated users to perform RCE | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Avinash Hanwate <ahanwate> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | adupliak, aileenc, aschwart, asoldano, ataylor, bbaranow, bmaxwell, boliveir, brian.stansberry, chazlett, cmiranda, darran.lofthouse, dhanak, dkreling, dosoudil, drichtar, drosa, fmariani, gmalinko, ibek, istudens, ivassile, iweiss, janstey, jkoops, jpoth, jrokos, kverlaen, mnovotny, mosmerov, mposolda, msochure, mstefank, msvehla, mulliken, nwallace, pberan, pbizzarr, pcongius, pdelbell, pdrozd, peholase, pesilva, pjindal, pmackay, pskopek, rguimara, rmartinc, rowaters, rstancel, rstepani, saroy, sausingh, smaestri, ssilvert, sthorger, tcunning, tom.jenkinson, vmuzikar, yfang |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | activemq 5.16.6, activemq 5.17.4, activemq 5.18.0, activemq 6.0.0 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A vulnerability in ActiveMQ's Jolokia integration, where an authenticated user can potentially execute arbitrary code on the server. The vulnerability stems from the ability to handle and manipulate JMX requests through Jolokia's HttpRequestHandler, allowing an attacker to exploit the jdk.management.jfr.FlightRecorderMXBeanImpl class in Java 11 or higher. By crafting specific requests, an attacker could inject and execute a webshell, leading to remote code execution. This poses a significant security risk, especially in environments where Jolokia is enabled and not properly secured.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2252186 | ||
|
Description
Avinash Hanwate
2023-11-30 03:07:24 UTC
This issue has been addressed in the following products: RHEL-8 based Middleware Containers Via RHSA-2024:2944 https://access.redhat.com/errata/RHSA-2024:2944 This issue has been addressed in the following products: Red Hat JBoss AMQ Via RHSA-2024:2945 https://access.redhat.com/errata/RHSA-2024:2945 This issue has been addressed in the following products: Red Hat Fuse 7.13.0 Via RHSA-2024:3354 https://access.redhat.com/errata/RHSA-2024:3354 |