漏洞描述
Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. Users are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.openwall.comhttp://www.openwall.com/lists/oss-security/2023/10/27/5↗activemq.apache.orghttps://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt↗github.comhttps://github.com/X1r0z/ActiveMQ-RCE↗attackerkb.comhttps://attackerkb.com/topics/IHsgZDE3tS/cve-2023-46604/rapid7-analysis?referrer=etrblog↗paper.seebug.orghttps://paper.seebug.org/3058/↗