Apache ActiveMQ Artemis is an open-source message broker. Security advisories for CVE-2021-26118 describe an OpenWire protocol issue in Artemis where advisory-message creation was not subject to the expected access-control checks, which could bypass policy-based access control for the session. [S1][S2][S3]
Impact
Affected deployments that run the vulnerable Artemis OpenWire component and expose OpenWire in a relevant broker configuration may allow clients to operate outside intended access-control policy. Repository dependency evidence alone does not prove that Artemis is deployed, OpenWire is enabled or reachable, advisory messages can be created by an attacker, or unauthorized message access occurred. [S1][S2][S4]
How FixVibe covers it
FixVibe's GitHub repo scans flag Maven and Gradle build files that resolve org.apache.activemq:artemis-openwire-protocol versions before 2.16.0, with the matched file, version and remediation guidance. [S2][S5]
Fixes
- Upgrade Apache ActiveMQ Artemis/OpenWire dependencies and deployed broker distributions to
2.16.0or later, or document a vendor-supported backport. [S2] - Regenerate Maven/Gradle dependency metadata and rebuild every broker image, embedded broker, integration-test service, and deployment artifact that can start Artemis.
- Disable OpenWire if it is not required, and keep OpenWire acceptors restricted to trusted networks and authenticated clients with least-privilege authorization. [S4]
