GHSA-3w85-5p9g-h334

Suggest an improvement
Source
https://github.com/advisories/GHSA-3w85-5p9g-h334
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-3w85-5p9g-h334/GHSA-3w85-5p9g-h334.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3w85-5p9g-h334
Aliases
  • CVE-2025-27427
Published
2025-04-01T09:30:19Z
Modified
2025-04-01T18:27:10.632724Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
Details

A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address.

This issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.0.

Users are recommended to upgrade to version 2.40.0 which fixes the issue.

Database specific
{
    "nvd_published_at": "2025-04-01T08:15:13Z",
    "cwe_ids": [
        "CWE-863"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2025-04-01T18:04:06Z"
}
References

Affected packages

Maven / org.apache.activemq:artemis-server

Package

Name
org.apache.activemq:artemis-server
View open source insights on deps.dev
Purl
pkg:maven/org.apache.activemq/artemis-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.40.0

Affected versions

2.*

2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.7.0
2.8.0
2.8.1
2.9.0
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.20.0
2.21.0
2.22.0
2.23.0
2.23.1
2.24.0
2.25.0
2.26.0
2.27.0
2.27.1
2.28.0
2.29.0
2.30.0
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.34.0
2.35.0
2.36.0
2.37.0
2.38.0
2.39.0