CVE-2021-26118
Apache ActiveMQ Artemis vulnerable to Improper Access Control
7.5
HIGH
CVSS 3.1
EPSS 1.0%
Description
While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.
How to fix CVE-2021-26118
To remediate CVE-2021-26118, upgrade the affected package to a fixed version below.
- —upgrade to 2.16.0 or later
Is CVE-2021-26118 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.16.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |