FixVibe

high

Apache ActiveMQ Artemis Diagnostic Information Exposure (CVE-2023-50780)

Apache ActiveMQ Artemis allows authenticated users to access diagnostic information and controls through MBeans via Jolokia. FixVibe GitHub repo scans flag affected Artemis dependencies for CVE-2023-50780.

CVE-2023-50780GHSA-443j-grxv-2pgvCWE-285

Impact

An authenticated attacker with access to the Jolokia endpoint can interact with sensitive Managed Beans (MBeans) [S1]. This allows for the retrieval of diagnostic information and the execution of control operations that should be restricted to administrative users [S1]. Specifically, exposure of the Log4J2 MBean in older versions could allow an attacker to manipulate logging configurations [S1].

Root Cause

Apache ActiveMQ Artemis utilizes Jolokia to provide a RESTful interface for JMX (Java Management Extensions). The vulnerability stems from an improper authorization check (CWE-285) where the authenticated Jolokia endpoint exposes MBeans that are not intended for general user access [S1]. In versions prior to 2.29.0, the default configuration included the Log4J2 MBean in the set of accessible objects through this interface [S1].

Remediation

Users should upgrade to Apache ActiveMQ Artemis version 2.29.0 or later, where the Log4J2 MBean is no longer exposed to non-administrative users through the Jolokia endpoint [S1]. Administrators should also review JMX and Jolokia access control policies so only necessary MBeans are reachable by trusted administrative roles.

Covered by FixVibe

FixVibe's GitHub repo scans flag projects that resolve an Apache ActiveMQ Artemis release affected by CVE-2023-50780 / GHSA-443j-grxv-2pgv, showing the dependency file, version and fixed release. While you upgrade, confirm that Jolokia and web-console access is limited to trusted administrators.