/Vulnerability Library

Apache ActiveMQ 6.x < 6.1.2 - Broken Access Control

CVE-2024-32114
Verified

Description

Apache ActiveMQ 6.x contains an unauthenticated API web context caused by default configuration lacking security measures in the Jetty server, letting anyone interact with broker APIs and messaging layers, exploit requires no authentication.

Severity

High

CVSS Score

8.8

Exploit Probability

7%

Affected Product

activemq

Published Date

May 2, 2026

Template Author

chrisjr404

CVE-2024-32114.yaml
8.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE ID:
cve-2024-32114
CWE ID:
cwe-1188

References

https://activemq.apache.org/security-advisories.data/CVE-2024-32114-announcement.txthttps://github.com/vulhub/vulhub/tree/master/activemq/CVE-2024-32114https://github.com/advisories/GHSA-gj5m-m88j-v7c3https://nvd.nist.gov/vuln/detail/CVE-2024-32114

Remediation Steps

Upgrade to Apache ActiveMQ 6.1.2 or later, or update `conf/jetty.xml` to require authentication on the `/api/` web context.