远程攻击者可以构造一个 OpenWire RemoveSubscriptionInfo 命令,从而在连接认证和授权阶段之前,或在此之后的任何时间,导致 Artemis 代理上的某个队列被删除。 此问题影响 Apache Artemis 的 2.50.0 至 2.56.0 版本,以及 Apache ActiveMQ Artemis 的 1.0.0 至 2.44.0 版本。 建议用户升级到 2.57.0 版本,该版本已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Artemis | 2.50.0 ~ 2.56.0 | - |
|
| Apache Software Foundation | Apache Artemis | 2.50.0 ~ 2.56.0 | - |
|
| Apache Software Foundation | Apache ActiveMQ Artemis | 1.0.0 ~ 2.44.0 | - |
|
| Apache Software Foundation | Apache ActiveMQ Artemis | 2.32.0 ~ 2.44.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80354 | Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secr | |
| CVE-2026-80351 | Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod | |
| CVE-2026-80352 | Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author appl | |
| CVE-2026-84939 | Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path trave | |
| CVE-2026-49362 | Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler A | |
| CVE-2026-49363 | Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE | |
| CVE-2026-49364 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Auth | |
| CVE-2026-57822 | Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserializatio | |
| CVE-2026-57967 | Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session r | |
| CVE-2026-75880 | Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to |
No comments yet