#VU50072 Improper Authentication in ActiveMQ and ActiveMQ Artemis - CVE-2021-26117
Published: January 27, 2021 / Updated: January 28, 2021
ActiveMQ
ActiveMQ Artemis
Apache Foundation
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to a logic error in ActiveMQ LDAP login module when configured to to use anonymous access to the LDAP server. A remote attacker can provide a valid username and no password and gain unauthorized access to the system.