CVE-2021-26117

CVE-2021-26117: ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind

Vendor Apache Software Foundation
Product Apache ActiveMQ
Weakness CWE-287 · Improper authentication
Published January 27, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

Key dates

02Disclosure timeline

January 27, 2021 CVE published
August 3, 2024 Record updated