[MAVEN:GHSA-23CR-5HR4-RGWV] Improper Input Validation in Apache ActiveMQ

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.

Package Affected Version
pkg:maven/org.apache.activemq/activemq-jaas >= 5.0.0, <= 5.10.1
pkg:maven/org.apache.activemq/activemq-broker >= 5.0.0, <= 5.10.1
ID
MAVEN:GHSA-23CR-5HR4-RGWV
Severity
moderate
URL
https://github.com/advisories/GHSA-23cr-5hr4-rgwv
Published
2022-05-17T03:22:06
(2 years ago)
Modified
2023-12-20T19:16:01
(9 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.activemq/activemq-jaas org.apache.activemq activemq-jaas >= 5.0.0 <= 5.10.1
Fixed pkg:maven/org.apache.activemq/activemq-jaas org.apache.activemq activemq-jaas = 5.10.2
Affected pkg:maven/org.apache.activemq/activemq-broker org.apache.activemq activemq-broker >= 5.0.0 <= 5.10.1
Fixed pkg:maven/org.apache.activemq/activemq-broker org.apache.activemq activemq-broker = 5.10.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...