2.53.0
10 years ago
20 days ago
Known vulnerabilities in the org.apache.activemq:artemis-server package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.apache.activemq:artemis-server is a server package for the ActiveMQ-Artemis project. Affected versions of this package are vulnerable to Missing Authentication for Critical Function via the Core protocol implementation. A malicious broker can force a broker to establish an outbound Core federation connection to it, and use it to inject or exfiltrate messages from the target broker. How to fix Missing Authentication for Critical Function? Upgrade | [2.11.0,2.52.0) |
org.apache.activemq:artemis-server is a server package for the ActiveMQ-Artemis project. Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File when the How to fix Insertion of Sensitive Information into Log File? Upgrade | [1.5.1,2.40.0) |
org.apache.activemq:artemis-server is a server package for the ActiveMQ-Artemis project. Affected versions of this package are vulnerable to Incorrect Authorization in the How to fix Incorrect Authorization? Upgrade | [2.0.0,2.40.0) |