← Back to Products

activemq_artemis

Vendor: apache

2
Total CVEs
0
Critical
2
High
0
Medium
0
Low

Recent CVEs

Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscripti...

Affected versions: 2.0.0 2.1.0 2.10.0 2.10.1 2.11.0 +49 more

Published: Mar 24, 2026

4.3

CVSS

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker t...

Affected versions: 2.11.0 2.12.0 2.13.0 2.14.0 2.15.0 +32 more

Published: Mar 4, 2026

9.8

CVSS

Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.Con...

Affected versions: 1.5.1 1.5.2 1.5.3 1.5.4 1.5.5 +52 more

Published: Apr 9, 2025

6.5

CVSS

A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address ev...

Affected versions: 2.0.0 2.1.0 2.10.0 2.10.1 2.11.0 +46 more

Published: Apr 1, 2025

4.3

CVSS

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also include...

Affected versions: 1.0.0 1.1.0 1.2.0 1.3.0 1.4.0 +45 more

Published: Oct 14, 2024

8.8

CVSS

It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may re...

Affected versions: 1.0.0 1.1.0 1.2.0 1.3.0 1.4.0 +11 more

Published: Mar 7, 2018

7.5

CVSS

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote auth...

Affected versions: 1.0.0 1.1.0 1.2.0 1.3.0

Published: Sep 27, 2016

7.2

CVSS