Back to Vulnerability Directory
HIGHFixed upstream

CVE-2021-26117

ActiveMQ Artemis: LDAP login module with anonymous bind does not check passwords

Technology

ActiveMQ Artemis

CVSS Score

7.5 / 10.0

Affected Versions

ActiveMQ Artemis before 2.16.0

Upstream Fix

2.16.0

Published

January 27, 2021

OSSeva Coverage

Fixed upstream

Description

When the optional LDAP login module is configured to use anonymous access to the LDAP server, the anonymous context is used in error to verify a user's password, so no password check takes place. The same flaw affected ActiveMQ Classic before 5.15.14 and 5.16.1. Apache rates it high.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running ActiveMQ Artemis before 2.16.0, you need this patch. Book a discovery call to get covered.