|
|
Message-ID: <d4968eca-7663-ec99-a26d-458e8c5a9e1a@apache.org> Date: Sun, 31 May 2026 16:17:37 +0000 From: "Christopher L. Shannon" <cshannon@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2026-46605: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal Severity: moderate Affected versions: - Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) before 5.19.7 - Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) 6.0.0 before 6.2.6 - Apache ActiveMQ All (org.apache.activemq:activemq-all) before 5.19.7 - Apache ActiveMQ All (org.apache.activemq:activemq-all) 6.0.0 before 6.2.6 - Apache ActiveMQ (org.apache.activemq:apache-activemq) before 5.19.7 - Apache ActiveMQ (org.apache.activemq:apache-activemq) 6.0.0 before 6.2.6 Description: Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue. Credit: Leon Johnson (github: lokerxx) (finder) References: https://activemq.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-46605
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.