Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-50780

ActiveMQ Artemis: Log4J2 MBean reachable through Jolokia lets an authenticated user write files

Technology

ActiveMQ Artemis

CVSS Score

8.8 / 10.0

Affected Versions

ActiveMQ Artemis before 2.29.0

Upstream Fix

2.29.0

Published

October 14, 2024

OSSeva Coverage

Fixed upstream

Description

Artemis exposes MBeans through the authenticated Jolokia endpoint. Before 2.29.0 these included the Log4J2 MBean, which is not meant for non-administrative users and can be used to write arbitrary files to the filesystem and, indirectly, to run code. Apache rates it moderate.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running ActiveMQ Artemis before 2.29.0, you need this patch. Book a discovery call to get covered.