Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 Buster DLA-3657-1: Critical ActiveMQ Remote Code Execution

debian lts
Calendar Grey November 20, 2023
Dist Debian Esm H88
Debian LTS DLA-3657-1 issued an advisory highlighting critical security vulnerabilities in ActiveMQ, accompanied by guidance on necessary updates.
Several security vulnerabilities have been discovered in ActiveMQ, a Java message broker

Summary

CVE-2020-13920

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI
registry and binds the server to the "jmxrmi" entry. It is possible to connect
to the registry without authentication and call the rebind method to rebind
jmxrmi to something else. If an attacker creates another server to proxy the
original, and bound that, he effectively becomes a man in the middle and is
able to intercept the credentials when an user connects.

CVE-2021-26117

The optional ActiveMQ LDAP login module can be configured to use anonymous
access to the LDAP server.

CVE-2023-46604

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution.
This vulnerability may allow a remote attacker with network access to either a
Java-based OpenWire broker or client to run arbitrary shell commands by
manipulating serialized class types in the OpenWire protocol to cause either
the client or the broker (respectively) to instantiate any class on the
classpath.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: activemq
Version: 5.15.16-0+deb10u1
CVE ID: CVE-2020-13920 CVE-2021-26117 CVE-2023-46604
Debian Bug: 1054909 982590

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here