CVE-2024-32114

Description

A flaw was found in Apache ActiveMQ. This vulnerability contains an insecure default configuration in Jolokia and REST API, allowing any user to bypass security restrictions. The vulnerability exists due to missing authorization in the application's REST API. The default configuration doesn't secure the API web context where the Jolokia JMX REST API and the Message REST API are located. This flaw allows an unauthenticated attacker to interact with the broker using the Jolokia JMX REST API to produce/consume messages or purge/delete destinations using the Message REST API.

Statement

The vulnerability in Apache ActiveMQ, stemming from insecure default configurations in its Jolokia JMX REST API and Message REST API, poses a critical threat due to the unrestricted access it grants to sensitive administrative functions. Without requiring proper authentication or authorization, malicious actors can exploit these APIs to perform unauthorized actions such as manipulating message queues, purging destinations, or intercepting message traffic. This potential for unauthorized access not only compromises the confidentiality and integrity of sensitive data within the messaging system but also exposes it to denial-of-service (DoS) attacks by disrupting message processing and delivery.

Mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.58.88.5
Attack VectorNetworkNetworkAdjacent Network
Attack ComplexityLowLowLow
Privileges RequiredNoneNoneNone
User InteractionNoneRequiredRequired
ScopeUnchangedUnchangedChanged
ConfidentialityNoneHighHigh
Integrity ImpactHighHighNone
Availability ImpactNoneHighHigh

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

cve.org: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

The impact of insecure defaults varies widely depending on the functionality that the product controls.

Frequently Asked Questions

Want to get errata notifications? Sign up here.