Improper Authentication in Apache ActiveMQ and Apache Artemis
High severity
GitHub Reviewed
Published
Jun 16, 2021
to the GitHub Advisory Database
•
Updated Mar 14, 2024
Description
Published by the National Vulnerability Database
Jan 27, 2021
Reviewed
Apr 5, 2021
Published to the GitHub Advisory Database
Jun 16, 2021
Last updated
Mar 14, 2024
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
References