Apache ActiveMQ Artemis
cpe:2.3:a:apache:activemq_artemis:*:*:*:*:*:*:*
- >= 2.0.0, <= 2.39.0
A vulnerability in Apache ActiveMQ Artemis allows users with queue creation permissions to modify the routing-type of addresses without having the necessary address creation permission. This issue, present in versions 2.0.0 through 2.39.0, could be exploited by users with send permission and automatic queue creation, enabling them to send messages with unsupported routing-types that should have been rejected.
Exploitation of this vulnerability could lead to messages being sent with routing-types not authorized for the user's address, bypassing intended permission controls.
Users are advised to upgrade to Apache ActiveMQ Artemis version 2.40.0, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.