Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-27427

ActiveMQ Artemis: queue-creation permission lets a user change an address's routing type

Technology

ActiveMQ Artemis

CVSS Score

4.3 / 10.0

Affected Versions

ActiveMQ Artemis 2.0.0 to 2.39.0

Upstream Fix

2.40.0

Published

April 1, 2025

OSSeva Coverage

Fixed upstream

Description

A user with createDurableQueue or createNonDurableQueue permission on an address can add a routing type the address does not support without the createAddress permission. Combined with send permission and automatic queue creation, the user can send a message with a routing type the address should reject. Apache rates it low.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running ActiveMQ Artemis 2.0.0 to 2.39.0, you need this patch. Book a discovery call to get covered.