FixVibe

high

Improper Access Control in Apache ActiveMQ Artemis (CVE-2021-26118)

CVE-2021-26118 is an improper access control issue in Apache ActiveMQ Artemis OpenWire handling before 2.16.0. FixVibe GitHub repo scans flag Maven and Gradle build files that resolve affected org.apache.activemq:artemis-openwire-protocol versions.

CVE-2021-26118GHSA-q7fr-vqhq-v5xrCWE-284CWE-287

Apache ActiveMQ Artemis is an open-source message broker. Security advisories for CVE-2021-26118 describe an OpenWire protocol issue in Artemis where advisory-message creation was not subject to the expected access-control checks, which could bypass policy-based access control for the session. [S1][S2][S3]

Impact

Affected deployments that run the vulnerable Artemis OpenWire component and expose OpenWire in a relevant broker configuration may allow clients to operate outside intended access-control policy. Repository dependency evidence alone does not prove that Artemis is deployed, OpenWire is enabled or reachable, advisory messages can be created by an attacker, or unauthorized message access occurred. [S1][S2][S4]

How FixVibe covers it

FixVibe's GitHub repo scans flag Maven and Gradle build files that resolve org.apache.activemq:artemis-openwire-protocol versions before 2.16.0, with the matched file, version and remediation guidance. [S2][S5]

Fixes

  • Upgrade Apache ActiveMQ Artemis/OpenWire dependencies and deployed broker distributions to 2.16.0 or later, or document a vendor-supported backport. [S2]
  • Regenerate Maven/Gradle dependency metadata and rebuild every broker image, embedded broker, integration-test service, and deployment artifact that can start Artemis.
  • Disable OpenWire if it is not required, and keep OpenWire acceptors restricted to trusted networks and authenticated clients with least-privilege authorization. [S4]