Back to Vulnerability Directory
HIGHFixed upstream
CVE-2021-26117
ActiveMQ Artemis: LDAP login module with anonymous bind does not check passwords
Technology
ActiveMQ Artemis
CVSS Score
7.5 / 10.0
Affected Versions
ActiveMQ Artemis before 2.16.0
Upstream Fix
2.16.0
Published
January 27, 2021
OSSeva Coverage
Fixed upstream
Description
When the optional LDAP login module is configured to use anonymous access to the LDAP server, the anonymous context is used in error to verify a user's password, so no password check takes place. The same flaw affected ActiveMQ Classic before 5.15.14 and 5.16.1. Apache rates it high.
Is your ActiveMQ Artemis deployment affected?
If you're running ActiveMQ Artemis before 2.16.0, you need this patch. Book a discovery call to get covered.