Apache ActiveMQ是Apache基金会的一款消息队列中间件。 Apache ActiveMQ存在授权问题漏洞,该漏洞源于授权不当,可能导致经过身份验证的低权限Web Console用户默认能访问/admin/*路径,而Jetty默认设置未正确限制这些路径仅允许管理员访问。以下版本受到影响:5.19.8之前版本和6.0.0至6.2.7之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache ActiveMQ | < 5.19.8 |
affected |
6.0.0< 6.2.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache ActiveMQ | 0 ~ 5.19.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54475 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination owners | |
| CVE-2026-53917 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbo | |
| CVE-2026-53916 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in ST | |
| CVE-2026-52760 | Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ | |
| CVE-2026-50750 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire | |
| CVE-2026-50734 | Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire | |
| CVE-2026-49432 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length | |
| CVE-2026-49434 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instant | |
| CVE-2025-53648 | Apache Gravitino: SQL misconfiguration can access or truncate files |
No comments yet