Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100Vexday Risk Score
Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.
ssvc Actcvss 10epss 100%
de la publicación al arma0 días
Publicada en NVD27 oct
1ª PoC26 oct
metasploit27 oct
CISA KEV+6d
probabilidad de explotación
100%top 1% de las CVE
explotación observada
síCISA + VulnCheck
64 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2023-11-23
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
The Java OpenWire protocol marshaller is vulnerable to Remote Code
Execution. This vulnerability may allow a remote attacker with network
access to either a Java-based OpenWire broker or client to run arbitrary
shell commands by manipulating serialized class types in the OpenWire
protocol to cause either the client or the broker (respectively) to
instantiate any class on the classpath.
Users are recommended to upgrade
both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3
which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
Productos afectados
Apache Software Foundation · Apache ActiveMQApache Software Foundation · Apache ActiveMQ Legacy OpenWire ModulePoCs públicas encontradas — 64
githubgithub.com/SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ★ 126githubgithub.com/Catherines77/ActiveMQ-EXPtools★ 77githubgithub.com/Arlenhiack/ActiveMQ-RCE-Exploit★ 43githubgithub.com/evkl1d/CVE-2023-46604★ 40githubgithub.com/trganda/ActiveMQ-RCE★ 28githubgithub.com/duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshell★ 18githubgithub.com/justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-exp★ 5githubgithub.com/vulncheck-oss/cve-2023-46604★ 4githubgithub.com/h3x3h0g/ActiveMQ-RCE-CVE-2023-46604-Write-up★ 3githubgithub.com/NKeshawarz/CVE-2023-46604-RCE★ 3githubgithub.com/LiritoShawshark/CVE-2023-46604_ActiveMQ_RCE_Recurrence★ 2githubgithub.com/dcm2406/CVE-Lab★ 2githubgithub.com/RockyDesigne/SSP-Assignment-3-RCEYouLater★ 2githubgithub.com/mrpentst/CVE-2023-46604★ 2githubgithub.com/vaishnavucv/Project-Vuln-Detection-N-Mitigation_101★ 1githubgithub.com/pulentoski/CVE-2023-46604★ 1githubgithub.com/skrkcb2/CVE-2023-46604★ 1githubgithub.com/stegano5/ExploitScript-CVE-2023-46604★ 1githubgithub.com/minhangxiaohui/ActiveMQ_CVE-2023-46604★ 1githubgithub.com/dcm2406/CVE-2023-46604★ 0githubgithub.com/vjayant93/CVE-2023-46604-POC★ 0githubgithub.com/CrackerCat/ActiveMQ_RCE_Pro_Max★ 0githubgithub.com/nitzanoligo/CVE-2023-46604-demo★ 0githubgithub.com/Mudoleto/Broker_ApacheMQ★ 0githubgithub.com/tomasmussi/activemq-cve-2023-46604★ 0githubgithub.com/thinkycx/activemq-rce-cve-2023-46604★ 0githubgithub.com/mranv/honeypot.rs★ 0githubgithub.com/cuanh2333/CVE-2023-46604★ 0githubgithub.com/CCIEVoice2009/CVE-2023-46604★ 0githubgithub.com/pavanaa4k/CVE-2023-46604-LAB★ 0githubgithub.com/sangrok-jeon/CVE-2023-46604-Analysis★ 0githubgithub.com/mkdemir/activemq-lockbit-analysis★ 0githubgithub.com/Navya240/intel471-threat-hunting-cve-2023-46604★ 0githubgithub.com/KlaasStessens/CVE-2023-46604★ 0githubgithub.com/trnguyen03/activemq-ids-ips-lab★ 0githubgithub.com/REGGYRAIDER/CVE-2023-46604-RCE★ 0githubgithub.com/aelshimony-cloud/OpenWire-CVE-2023-46604-Investigation★ 0vulncheckvulncheck.com/xdb/ac860bc0b755no verificadovulncheckvulncheck.com/xdb/1e134f0874f8no verificadovulncheckvulncheck.com/xdb/5f38a93c3fe0no verificadovulncheckvulncheck.com/xdb/c01880ea274bno verificadovulncheckvulncheck.com/xdb/2a263bac5fa9no verificadovulncheckvulncheck.com/xdb/90299d8578e8no verificadovulncheckvulncheck.com/xdb/7adf2c60412fno verificadovulncheckvulncheck.com/xdb/c1ad06a8233fno verificadovulncheckvulncheck.com/xdb/d6b987f7cb4cno verificadovulncheckvulncheck.com/xdb/adc63f08a561no verificadovulncheckvulncheck.com/xdb/111d5aa9554fno verificadovulncheckvulncheck.com/xdb/7d454efa423fno verificadovulncheckvulncheck.com/xdb/f688c01da056no verificadovulncheckvulncheck.com/xdb/26ec274f11a6no verificadovulncheckvulncheck.com/xdb/bd01e441da28no verificadovulncheckvulncheck.com/xdb/cc4ca3b4d289no verificadovulncheckvulncheck.com/xdb/9c19a15a7306no verificadovulncheckvulncheck.com/xdb/9af52ad961ceno verificadovulncheckvulncheck.com/xdb/bf84564c744cno verificadovulncheckvulncheck.com/xdb/e3eff001f1dbno verificadocve_referencepacketstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.htmlno verificadovulncheckvulncheck.com/xdb/453453dd752fno verificadovulncheckvulncheck.com/xdb/f5d0e2739b8cno verificadovulncheckvulncheck.com/xdb/8ce9f74afedcno verificadovulncheckvulncheck.com/xdb/28c5231dc0c7no verificadovulncheckvulncheck.com/xdb/07dca85f6442no verificadovulncheckvulncheck.com/xdb/0462e934919bno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txthttp://seclists.org/fulldisclosure/2024/Apr/18https://lists.debian.org/debian-lts-announce/2023/11/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2024/10/msg00027.htmlhttps://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.htmlhttps://security.netapp.com/advisory/ntap-20231110-0010/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46604https://www.openwall.com/lists/oss-security/2023/10/27/5