CVE-2023-50780

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 14, 2024
Updated: Mar 19, 2025
CWE ID 285

Summary

CVE-2023-50780 is a vulnerability affecting Apache ActiveMQ Artemis before version 2.29.0. The issue involves unintended exposure of diagnostic information and controls through MBeans, which are accessible via the Jolokia endpoint. This includes the Log4J2 MBean, which should not be accessible to non-administrative users. An authenticated attacker could exploit this vulnerability to write arbitrary files to the filesystem, potentially leading to remote code execution. It is strongly advised to upgrade to version 2.29.0 or later to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apache ActiveMQ Artemis

Affected Vendors

  • Apache Software Foundation
  • Apache Corporation