Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary dest
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N약점 (CWE)
- CWE-862
권한 검사 누락 — 접근 권한 확인 없이 기능/자원에 접근 허용.
상세 설명
Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only checked in the client, allowing a different connection to consume from another connection's temporary
destination.
This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7, which fixes the issue.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- apache activemq< 5.19.8other
- apache activemq6.0.0 - 6.2.7other
- apache activemq_broker< 5.19.8other
- apache activemq_broker6.0.0 - 6.2.7other
영향받는 구성 (CPE) 2
- apache activemq< 5.19.8cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
- apache activemq_broker< 5.19.8cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
참고 자료 2
- https://lists.apache.org/thread/85f3q7mkh71y7qwyn6wvgw0bw4jl06ysVendor AdvisoryMailing List
- http://www.openwall.com/lists/oss-security/2026/06/29/15Third Party Advisory
링크 내용 불러오는 중…