CVE-2025-27427

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
01/04/2025
Last modified:
01/04/2025

Description

A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn&amp;#39;t have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesn&amp;#39;t have permission to change the routing-type of the address.<br /> <br /> This issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.0.<br /> <br /> Users are recommended to upgrade to version 2.40.0 which fixes the issue.

References to Advisories, Solutions, and Tools