Неправильная проверка ввода в TopicRegion в Apache ActiveMQ, Apache ActiveMQ Broker и Apache ActiveMQ All на всех платформах. Клиент, прошедший проверку подлинности, может подделать clientId при удалении подписки на постоянную тему. Эта проблема затрагивает Apache ActiveMQ Broker: до 5.19.11, от 6.0.0 до 6.3.2; Apache ActiveMQ Все: до 5.19.11, от 6.0.0 до 6.3.2; Apache ActiveMQ: до версии 5.19.11, от версии 6.0.0 до версии 6.3.2.
Пользователям рекомендуется выполнить обновление до версии 6.3.2 или 5.19.11, которая устраняет проблему.
Показать оригинальное описание (EN)
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2. Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.
Характеристики атаки
Последствия
Строка CVSS v3.1
Тип уязвимости (CWE)
Уязвимые продукты 6
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Apache Activemq
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
|
— |
5.19.11
|
|
Apache Activemq
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
|
6.0.0
|
6.3.2
|
|
Apache Activemq_All
cpe:2.3:a:apache:activemq_all:*:*:*:*:*:*:*:*
|
— |
5.19.11
|
|
Apache Activemq_All
cpe:2.3:a:apache:activemq_all:*:*:*:*:*:*:*:*
|
6.0.0
|
6.3.2
|
|
Apache Activemq_Broker
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
|
— |
5.19.11
|
|
Apache Activemq_Broker
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
|
6.2.0
|
6.3.2
|