{"id":"GHSA-crg9-44h2-xw35","summary":"Apache ActiveMQ is vulnerable to Remote Code Execution","details":"Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. \n\nUsers are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.","aliases":["BIT-activemq-2023-46604","CVE-2023-46604"],"modified":"2025-11-04T00:48:45.863602Z","published":"2023-10-27T15:30:20Z","database_specific":{"github_reviewed_at":"2023-10-30T20:08:40Z","nvd_published_at":"2023-10-27T15:15:14Z","cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46604"},{"type":"WEB","url":"https://github.com/apache/activemq/pull/1098"},{"type":"WEB","url":"https://github.com/apache/activemq/commit/22442b2385b1000312aec3d19e510131d595a5fc"},{"type":"WEB","url":"https://github.com/apache/activemq/commit/80089f9f476afab7d976f5fc37c5ab4aa0c2139d"},{"type":"WEB","url":"https://github.com/apache/activemq/commit/958330df26cf3d5cdb63905dc2c6882e98781d8f"},{"type":"WEB","url":"https://github.com/apache/activemq/commit/9905e2a5bf9862a049f94ce0a2465b0c7ad52436"},{"type":"WEB","url":"https://github.com/apache/activemq/commit/d0ccdd31544ada83185554c87c7aa141064020f0"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/10/27/5"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46604"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20231110-0010"},{"type":"WEB","url":"https://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/10/msg00027.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/AMQ-9370"},{"type":"PACKAGE","url":"https://github.com/apache/activemq"},{"type":"WEB","url":"https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt"},{"type":"WEB","url":"https://activemq.apache.org/security-advisories.data/CVE-2023-46604"},{"type":"WEB","url":"http://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Apr/18"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/10/27/5"}],"affected":[{"package":{"name":"org.apache.activemq:activemq-client","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.16"}]}],"versions":["5.10.0","5.10.1","5.10.2","5.11.0","5.11.1","5.11.2","5.11.3","5.11.4","5.12.0","5.12.1","5.12.2","5.12.3","5.13.0","5.13.1","5.13.2","5.13.3","5.13.4","5.13.5","5.14.0","5.14.1","5.14.2","5.14.3","5.14.4","5.14.5","5.15.0","5.15.1","5.15.10","5.15.11","5.15.12","5.15.13","5.15.14","5.15.15","5.15.2","5.15.3","5.15.4","5.15.5","5.15.6","5.15.7","5.15.8","5.15.9","5.8.0","5.9.0","5.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json"}},{"package":{"name":"org.apache.activemq:activemq-client","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"5.16.7"}]}],"versions":["5.16.0","5.16.1","5.16.2","5.16.3","5.16.4","5.16.5","5.16.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json"}},{"package":{"name":"org.apache.activemq:activemq-client","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.17.0"},{"fixed":"5.17.6"}]}],"versions":["5.17.0","5.17.1","5.17.2","5.17.3","5.17.4","5.17.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json"}},{"package":{"name":"org.apache.activemq:activemq-client","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.18.0"},{"fixed":"5.18.3"}]}],"versions":["5.18.0","5.18.1","5.18.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json"}},{"package":{"name":"org.apache.activemq:activemq-openwire-legacy","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-openwire-legacy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.8.0"},{"fixed":"5.15.16"}]}],"versions":["5.10.0","5.10.1","5.10.2","5.11.0","5.11.1","5.11.2","5.11.3","5.11.4","5.12.0","5.12.1","5.12.2","5.12.3","5.13.0","5.13.1","5.13.2","5.13.3","5.13.4","5.13.5","5.14.0","5.14.1","5.14.2","5.14.3","5.14.4","5.14.5","5.15.0","5.15.1","5.15.10","5.15.11","5.15.12","5.15.13","5.15.14","5.15.15","5.15.2","5.15.3","5.15.4","5.15.5","5.15.6","5.15.7","5.15.8","5.15.9","5.8.0","5.9.0","5.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json"}},{"package":{"name":"org.apache.activemq:activemq-openwire-legacy","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-openwire-legacy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"5.16.7"}]}],"versions":["5.16.0","5.16.1","5.16.2","5.16.3","5.16.4","5.16.5","5.16.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json"}},{"package":{"name":"org.apache.activemq:activemq-openwire-legacy","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-openwire-legacy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.17.0"},{"fixed":"5.17.6"}]}],"versions":["5.17.0","5.17.1","5.17.2","5.17.3","5.17.4","5.17.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json"}},{"package":{"name":"org.apache.activemq:activemq-openwire-legacy","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-openwire-legacy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.18.0"},{"fixed":"5.18.3"}]}],"versions":["5.18.0","5.18.1","5.18.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H/E:H"}]}