CVE-2021-26117

NameCVE-2021-26117
DescriptionThe optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2583-1
NVD severitymedium
Debian Bugs982590

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
activemq (PTS)stretch5.14.3-3vulnerable
stretch (security)5.14.3-3+deb9u2fixed
buster5.15.8-2vulnerable
bullseye, sid5.16.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
activemqsourcestretch5.14.3-3+deb9u2DLA-2583-1
activemqsource(unstable)5.16.1-1982590

Notes

https://issues.apache.org/jira/browse/AMQ-8035
https://www.openwall.com/lists/oss-security/2021/01/27/6
https://gitbox.apache.org/repos/asf?p=activemq.git;h=c9f68f4c64b2687eee283b95538753665d2b229b

Search for package or bug name: Reporting problems