« Volver al listado

Apache

Apache Artemis: vulnerabilidades y CVE

Apache Artemis tiene 25 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE25
Últimos 12 meses12
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-67593Crítica (9.1)0.86%—10 sept 2026
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This…
CVE-2026-57967Crítica (9.8)1.1%—10 sept 2026
An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis:…
CVE-2026-57822Media (6.5)0.70%—10 sept 2026
When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can…
CVE-2026-49364Crítica (9.1)0.57%—10 sept 2026
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through…
CVE-2026-49363Alta (7.5)0.80%—10 sept 2026
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0…
CVE-2026-49362Alta (7.5)0.82%—10 sept 2026
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from…
CVE-2026-75880Media (6.5)0.65%—10 sept 2026
An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to…
CVE-2026-86404Alta (8.8)0.85%—7 sept 2026
EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its…
CVE-2026-40914Media (4.3)0.56%—28 may 2026
A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routing-type supported by…
CVE-2026-4649Media (5.3)0.50%—24 mar 2026
Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and injection of new message ( CVE-2026-27446 https://www.cve.org/CVERecord ).…
CVE-2026-32642Baja (2.3)0.56%—24 mar 2026
Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address…
CVE-2026-27446Crítica (9.3)1.2%—4 mar 2026
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an…
CVE-2025-27391Media (6.8)0.43%—9 abr 2025
Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl…
CVE-2025-27427Baja (2.3)0.64%—1 abr 2025
A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user…
CVE-2023-50780Alta (8.8)17%—14 oct 2024
Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean.…
CVE-2024-47817Media (5.3)0.40%—7 oct 2024
Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph…
CVE-2021-4040Media (5.3)3.1%—24 ago 2022
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the…
CVE-2022-35278Media (6.1)1.7%—23 ago 2022
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
CVE-2022-23913Alta (7.5)2.7%—4 feb 2022
In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.
CVE-2021-26118Alta (7.5)3.9%—27 ene 2021
While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session.…
CVE-2021-26117Alta (7.5)11%—27 ene 2021
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and…
CVE-2020-13932Media (6.1)4.3%—20 jul 2020
In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's…
CVE-2020-10727Media (5.5)0.70%—26 jun 2020
A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when…
CVE-2017-12174Alta (7.5)6.0%—7 mar 2018
It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap…
CVE-2016-4978Alta (7.2)6.9%—27 sept 2016
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application6
  2. T1078 Valid Accounts3
  3. T1059 Command and Scripting Interpreter1
  4. T1210 Exploitation of Remote Services1
  5. T1499.004 Application or System Exploitation1
  6. T1552.007 Container API1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Apache