CyberRota Analysis
AI-GeneratedApache Artemis and Apache ActiveMQ Artemis versions 2.50.0 through 2.56.0 and 1.0.0 through 2.44.0, respectively, are vulnerable to a remote attack that can exploit the Openwire RemoveSubscriptionInfo command, leading to the unauthorized deletion of queues before or after connection authentication. This vulnerability poses a significant risk to environments relying on these messaging brokers, making it critical for users to prioritize upgrading to version 2.57.0 to mitigate potential data loss and service disruption. Organizations utilizing these affected versions should take immediate action to secure their systems.
Original NVD Description
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.