CVE-2021-26118: Flaw in ActiveMQ Artemis OpenWire support
While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.activemq:artemis-openwire-protocolto a version that resolves this vulnerability.Fixed in 2.16.0
Event History
Frequently Asked Questions
What is CVE-2021-26118?
CVE-2021-26118 is a vulnerability that allows the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 to bypass policy based access control.
How does CVE-2021-26118 affect Apache ActiveMQ Artemis?
CVE-2021-26118 affects Apache ActiveMQ Artemis 2.15.0 by allowing the creation of advisory messages without proper access control.
What is the severity of CVE-2021-26118?
CVE-2021-26118 has a severity rating of 7.5 (High).
How can I fix CVE-2021-26118?
To fix CVE-2021-26118, you should upgrade to Apache ActiveMQ Artemis 2.16.0 or a later version.
Where can I find more information about CVE-2021-26118?
You can find more information about CVE-2021-26118 on the NIST National Vulnerability Database (NVD) website.