CVE-2023-50780

CVE-2023-50780: Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans

Vendor Apache Software Foundation
Product Apache ActiveMQ Artemis
Weakness CWE-285
Published October 14, 2024
Last update March 19, 2025

CVSS base score

What the vulnerability does

Description

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an authenticated attacker to write arbitrary files to the filesystem and indirectly achieve RCE. Users are recommended to upgrade to version 2.29.0 or later, which fixes the issue.

Key dates

Disclosure timeline

October 14, 2024 CVE published
March 19, 2025 Record updated