Bug 2278791 (CVE-2024-32114) - CVE-2024-32114 activemq-broker: Jolokia and REST API were not secured with default configuration
Summary: CVE-2024-32114 activemq-broker: Jolokia and REST API were not secured with de...
Keywords:
Status: NEW
Alias: CVE-2024-32114
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2278796
TreeView+ depends on / blocked
 
Reported: 2024-05-03 05:37 UTC by TEJ RATHI
Modified: 2025-03-13 12:08 UTC (History)
41 users (show)

Fixed In Version: ActiveMQ 6.1.2, ActiveMQ 6.2.0
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description TEJ RATHI 2024-05-03 05:37:49 UTC
In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, anyone can interact with the broker (using Jolokia JMX REST API) and/or produce/consume messages or purge/delete destinations (using the Message REST API).

https://activemq.apache.org/security-advisories.data/CVE-2024-32114-announcement.txt
https://issues.apache.org/jira/browse/AMQ-9477


Note You need to log in before you can comment on or make changes to this bug.