Executive brief
Apache ActiveMQ is vulnerable to remote code execution due to insecure deserialization in the OpenWire protocol marshaller. A remote attacker can exploit this by manipulating serialized class types to instantiate arbitrary classes on the classpath, allowing for the execution of shell commands on both brokers and clients.
Affected products
- Apache ActiveMQ < 5.15.16, < 5.16.7, < 5.17.6, < 5.18.3
Timeline
- 2023-10-27: disclosed: Initial public disclosure via oss-security mailing list.
- 2023-11-02: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2023-11-02: advisory: NVD publication date.