CyberRota Analysis
AI-GeneratedImproper input validation in the TopicRegion component of Apache ActiveMQ allows authenticated clients to spoof the clientId when removing durable topic subscriptions, potentially leading to unauthorized access or manipulation of message subscriptions. This vulnerability affects versions prior to 5.19.11 and from 6.0.0 before 6.3.2 across all platforms. Organizations using affected versions should prioritize upgrading to version 6.3.2 or 5.19.11 to mitigate this risk.
Original NVD Description
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ AllĀ on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2. Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.