CVE-2025-27427
Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
01/04/2025
Last modified:
01/04/2025
Description
A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn&#39;t have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesn&#39;t have permission to change the routing-type of the address.<br />
<br />
This issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.0.<br />
<br />
Users are recommended to upgrade to version 2.40.0 which fixes the issue.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW