Apache ActiveMQ Artemis 在 2.34.0 之前的版本中存在一个不安全的反射漏洞,位于 方法中。该方法调用 ,其中 直接从 CORE 协议的数据包缓冲区中读取,且未进行任何类型验证。经过身份验证的联邦对等节点(federation peer)可以发送一个经过构造的 数据包,携带恶意的类名,从而诱使 Broker 加载并实例化 Artemis 模块类加载器可见的任意类。在类型转换之前,类的静态初始化器( )和无参构造函数( )会作为副作用被执行,这可能导致拒绝服务(DoS)攻击,具体表现包括:通
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat AMQ Broker 7 | - |
cpe:/a:redhat:amq_broker:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet