Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
In short
Apache ActiveMQ brokers with network connectors can leak sensitive subscription information to unauthenticated attackers. An attacker can obtain details about durable topic subscriptions, client IDs, and filtering rules without logging in.
Technical detail
An unauthenticated attacker can send a crafted BrokerInfo command via OpenWire protocol to brokers configured with syncDurableSubs=true, exploiting missing authentication checks to enumerate all durable subscription metadata including client identifiers, subscription names, destinations, and JMS selector expressions. The vulnerability affects ActiveMQ versions before 5.19.7 and 6.0.0-6.2.5, and requires the broker to have network connectors enabled.
Summary generated and translated by AI from the official description.
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N