Skip to main content

Insecure Default Initialization of Resource

CVE-2024-32114

Severity High
Score 8.5/10

Summary

In Apache ActiveMQ versions 6.0.0 through 6.1.1, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, anyone can interact with the broker (using Jolokia JMX REST API) and/or "produce/consume" messages or "purge/delete" destinations (using the Message REST API). To mitigate, users can update the default "conf/jetty.xml" configuration file to add authentication requirement "<bean id="securityConstraintMapping" class="org.eclipse.jetty.security.ConstraintMapping">", "<property name="constraint" ref="securityConstraint" />", "<property name="pathSpec" value="/" /> </bean>" Or we encourage users to upgrade to Apache ActiveMQ, where the default configuration has been updated with authentication by default.

  • LOW
  • ADJACENT_NETWORK
  • NONE
  • CHANGED
  • REQUIRED
  • NONE
  • HIGH
  • HIGH

CWE-1188 - Insecure Default Initialization of Resource

The software initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.

Advisory Timeline

  • Published