Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2025-27427
ActiveMQ Artemis: queue-creation permission lets a user change an address's routing type
Technology
ActiveMQ Artemis
CVSS Score
4.3 / 10.0
Affected Versions
ActiveMQ Artemis 2.0.0 to 2.39.0
Upstream Fix
2.40.0
Published
April 1, 2025
OSSeva Coverage
Fixed upstream
Description
A user with createDurableQueue or createNonDurableQueue permission on an address can add a routing type the address does not support without the createAddress permission. Combined with send permission and automatic queue creation, the user can send a message with a routing type the address should reject. Apache rates it low.
Is your ActiveMQ Artemis deployment affected?
If you're running ActiveMQ Artemis 2.0.0 to 2.39.0, you need this patch. Book a discovery call to get covered.