CVE-2023-46604
CRITICAL KEV CISA Exploitation: ACTIVE
Ransomware noto
10.0
CVSS 3.1
Description
The Java OpenWire protocol marshaller is vulnerable to Remote Code
Execution. This vulnerability may allow a remote attacker with network
access to either a Java-based OpenWire broker or client to run arbitrary
shell commands by manipulating serialized class types in the OpenWire
protocol to cause either the client or the broker (respectively) to
instantiate any class on the classpath.
Users are recommended to upgrade
both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3
which fixes this issue.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
SSVC — CISA Coordinator
CISA Known Exploited Vulnerability
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA description
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache ActiveMQ | — | 5.18.0 < 5.18.3, 5.17.0 < 5.17.6, 5.16.0 < 5.16.7, 0 < 5.15.16 |
| Apache Software Foundation | Apache ActiveMQ Legacy OpenWire Module | — | 5.18.0 < 5.18.3, 5.17.0 < 5.17.6, 5.16.0 < 5.16.7, 5.8.0 < 5.15.16 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-502 | cna | CWE-502 Deserialization of Untrusted Data |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H |
References (6)
- https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt
- https://www.openwall.com/lists/oss-security/2023/10/27/5
- https://security.netapp.com/advisory/ntap-20231110-0010/
- https://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html
- https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html
- http://seclists.org/fulldisclosure/2024/Apr/18