Junglewise Threat Intelligence

CVE-2023-46604: Apache ActiveMQ is vulnerable to Remote Code Execution

CVE-2023-46604 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2023-10-27

Technologies: Apache ActiveMQ. Vendors: Apache.

Executive brief

Apache ActiveMQ is vulnerable to remote code execution due to insecure deserialization in the OpenWire protocol marshaller. A remote attacker can exploit this by manipulating serialized class types to instantiate arbitrary classes on the classpath, allowing for the execution of shell commands on both brokers and clients.

Affected products

  • Apache ActiveMQ < 5.15.16, < 5.16.7, < 5.17.6, < 5.18.3

Timeline

  • 2023-10-27: disclosed: Initial public disclosure via oss-security mailing list.
  • 2023-11-02: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2023-11-02: advisory: NVD publication date.

Related threats