Back to Vulnerability Directory
HIGHFixed upstream
CVE-2024-32114
Apache ActiveMQ 6.x leaves the Jolokia and REST APIs unauthenticated by default
Technology
Apache ActiveMQ
CVSS Score
8.8 / 10.0
Affected Versions
6.0.0 before 6.1.2
Upstream Fix
6.1.2
Published
May 2, 2024
OSSeva Coverage
Fixed upstream
Description
In ActiveMQ 6.x before 6.1.2 the default configuration does not secure the API web context that holds the Jolokia JMX REST API and the Message REST API. Anyone who can reach it can manage the broker through Jolokia, and produce, consume, purge or delete through the Message REST API.
Is your Apache ActiveMQ deployment affected?
If you're running 6.0.0 before 6.1.2, you need this patch. Book a discovery call to get covered.