CVE-2021-26118

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:activemq_artemis:2.15.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:55

Type Values Removed Values Added
References () https://lists.apache.org/thread.html/rafd5d7cf303772a0118865262946586921a65ebd98fc24f56c812574%40%3Cannounce.apache.org%3E - () https://lists.apache.org/thread.html/rafd5d7cf303772a0118865262946586921a65ebd98fc24f56c812574%40%3Cannounce.apache.org%3E -
References () https://mail-archives.apache.org/mod_mbox/activemq-users/202101.mbox/%3CCAH%2BvQmMUNnkiXv2-d3ucdErWOsdnLi6CgnK%2BVfixyJvTgTuYig%40mail.gmail.com%3E - Mailing List, Vendor Advisory () https://mail-archives.apache.org/mod_mbox/activemq-users/202101.mbox/%3CCAH%2BvQmMUNnkiXv2-d3ucdErWOsdnLi6CgnK%2BVfixyJvTgTuYig%40mail.gmail.com%3E - Mailing List, Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20210827-0002/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20210827-0002/ - Third Party Advisory

07 Nov 2023, 03:31

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/rafd5d7cf303772a0118865262946586921a65ebd98fc24f56c812574@%3Cannounce.apache.org%3E', 'name': '[announce] 20210127 CVE-2021-26118: Flaw in ActiveMQ Artemis OpenWire support', 'tags': ['Mailing List', 'Patch', 'Vendor Advisory'], 'refsource': 'MLIST'}
  • () https://lists.apache.org/thread.html/rafd5d7cf303772a0118865262946586921a65ebd98fc24f56c812574%40%3Cannounce.apache.org%3E -

Information

Published : 2021-01-27 19:15

Updated : 2024-11-21 05:55


NVD link : CVE-2021-26118

Mitre link : CVE-2021-26118

CVE.ORG link : CVE-2021-26118


JSON object : View

Products Affected

apache

  • activemq_artemis

netapp

  • oncommand_workflow_automation
CWE
CWE-284

Improper Access Control

NVD-CWE-Other