CVE-2021-26117

NameCVE-2021-26117
DescriptionThe optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2583-1, DLA-3657-1
Debian Bugs982590

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
activemq (PTS)jessie, jessie (lts)5.6.0+dfsg1-4+deb8u3vulnerable
stretch (security)5.14.3-3+deb9u2fixed
stretch (lts), stretch5.14.3-3+deb9u3fixed
buster, buster (lts)5.15.16-0+deb10u2fixed
buster (security)5.15.16-0+deb10u1fixed
bullseye5.16.1-1fixed
bullseye (security)5.16.1-1+deb11u1fixed
bookworm (security), bookworm5.17.2+dfsg-2+deb12u1fixed
sid, trixie5.17.6+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
activemqsourcestretch5.14.3-3+deb9u2DLA-2583-1
activemqsourcebuster5.15.16-0+deb10u1DLA-3657-1
activemqsource(unstable)5.16.1-1982590

Notes

https://issues.apache.org/jira/browse/AMQ-8035
https://www.openwall.com/lists/oss-security/2021/01/27/6
https://gitbox.apache.org/repos/asf?p=activemq.git;h=c9f68f4c64b2687eee283b95538753665d2b229b

Search for package or bug name: Reporting problems