Apache ActiveMQ官网安全更新(2020-09-10)

情报来源:TSRC

发布时间:2020-09-10

基本信息
  • 发布日期2020-09-10
  • 感知时间2020-09-10
  • 漏洞类型安全更新
  • 风险等级中危
  • 更新版本 5.x
  • 情报贡献TSRC
更新标题

JMX MITM vulnerability

更新详情

CVE-2020-13920: Apache ActiveMQ JMX is vulnerable to a MITM attack<br/><br/>Severity: Moderate<br/><br/>Vendor: The Apache Software Foundation<br/><br/>Affected Version: Apache ActiveMQ version prior to 5.15.12<br/><br/>Vulnerability details:<br/>Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI<br/>registry and binds the server to the &#34;jmxrmi&#34; entry. It is possible<br/>to connect to the registry without authentication and call the rebind<br/>method to rebind jmxrmi to something else. If an attacker creates another<br/>server to proxy the original, and bound that, he effectively becomes a <br/>man in the middle and is able to intercept the credentials when an user<br/>connects.<br/><br/>Mitigation:<br/>Upgrade to Apache ActiveMQ 5.15.12<br/><br/>Credit: Jonathan Gallimore &amp; Colm O hEigeartaigh<br/>

软件描述

Apache ActiveMQ是Apache软件基金会所研发的开放源代码消息中间件;由于ActiveMQ是一个纯Java程序,因此只需要操作系统支持Java虚拟机,ActiveMQ便可执行。

CVE编号

<p><a target="_blank" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13920">CVE-2020-13920</a></p>

Knowsafe分析

暂无

业界资讯

暂无

来源链接

http://activemq.apache.org/security-advisories.data/CVE-2020-13920-announcement.txt