vulnerability

Red Hat JBoss EAP: CVE-2025-27427: Incorrect Authorization

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
Apr 1, 2025
Added
Apr 3, 2025
Modified
Nov 26, 2025

Description

A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address.
This issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.0.
Users are recommended to upgrade to version 2.40.0 which fixes the issue.. A flaw was found in Apache ActiveMQ Artemis. This vulnerability allows a user with createDurableQueue or createNonDurableQueue permissions to augment the routing-type of an address without the createAddress permission. When combined with the send permission and automatic queue creation, an attacker could send messages with unsupported routing-types, bypassing intended restrictions.

Solution

red-hat-jboss-eap-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.