← Πίσω στην αναζήτηση CVE

CVE-2026-41044

Apache ActiveMQ

Περιγραφή

Improper Input Validation, Improper Control of Generation of Code (-Code Injection-) vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding that can be later used by a VM transport to load a remote Spring XML application. The attacker can then use the DestinationView mbean to send a message to trigger a VM transport creation that will reference this malicious broker name which can lead to loading the malicious Spring XML context file. Because Spring-s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker-s JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Broker: before 5.19.6, from 6.0.0 before 6.2.5; Ap...

CVSS 8.8EPSS 0.98%Κίνδυνος 0.96
Προβολή πηγής
Δημοσίευση
2026-04-24 11:16:22
Επηρεαζόμενες εκδόσεις
<5.19.6
Τύπος
Core software
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H