Back to Vulnerability Directory
HIGHFixed upstream
CVE-2023-50780
ActiveMQ Artemis: Log4J2 MBean reachable through Jolokia lets an authenticated user write files
Technology
ActiveMQ Artemis
CVSS Score
8.8 / 10.0
Affected Versions
ActiveMQ Artemis before 2.29.0
Upstream Fix
2.29.0
Published
October 14, 2024
OSSeva Coverage
Fixed upstream
Description
Artemis exposes MBeans through the authenticated Jolokia endpoint. Before 2.29.0 these included the Log4J2 MBean, which is not meant for non-administrative users and can be used to write arbitrary files to the filesystem and, indirectly, to run code. Apache rates it moderate.
Is your ActiveMQ Artemis deployment affected?
If you're running ActiveMQ Artemis before 2.29.0, you need this patch. Book a discovery call to get covered.