Back to Vulnerability Directory
HIGHFixed upstream

CVE-2024-32114

Apache ActiveMQ 6.x leaves the Jolokia and REST APIs unauthenticated by default

Technology

Apache ActiveMQ

CVSS Score

8.8 / 10.0

Affected Versions

6.0.0 before 6.1.2

Upstream Fix

6.1.2

Published

May 2, 2024

OSSeva Coverage

Fixed upstream

Description

In ActiveMQ 6.x before 6.1.2 the default configuration does not secure the API web context that holds the Jolokia JMX REST API and the Message REST API. Anyone who can reach it can manage the broker through Jolokia, and produce, consume, purge or delete through the Message REST API.

Upstream record: NVD · CVE.org

Is your Apache ActiveMQ deployment affected?

If you're running 6.0.0 before 6.1.2, you need this patch. Book a discovery call to get covered.