GHSA-wqfh-9m4g-7x6x
CRITICALCVE-2020-11998A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack - A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security ma
- Affected
- >=5.15.12, = 5.15.12
- Fixed in
- 5.15.13
- Weakness
- CWE-94
- Published
- 2022-02-09
- Source
- github