{"id":"CVE-2021-26117","details":"The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.","aliases":["BIT-activemq-2021-26117","GHSA-9mgm-gcq8-86wq"],"modified":"2026-04-10T04:31:12.175695Z","published":"2021-01-27T19:15:13.720Z","references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r519bfafd67091d0b91243efcb1c49b1eea27321355ba5594f679277d%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r70389648227317bdadcdecbd9f238571a6047469d156bd72bb0ca2f7%40%3Cgitbox.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ra255ddfc8b613b80e9fa22ff3e106168b245f38a22316bfb54d21159%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rec93794f8aeddf8a5f1a643d264b4e66b933f06fd72a38f31448f0ac%40%3Cgitbox.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html"},{"type":"WEB","url":"https://mail-archives.apache.org/mod_mbox/activemq-users/202101.mbox/%3cCAH+vQmMeUEiKN4wYX9nLBbqmFZFPXqajNvBKmzb2V8QZANcSTA%40mail.gmail.com%3e"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r22cdc0fb45e223ac92bc2ceff7af92f1193dfc614c8b248534456229%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r5899ece90bcae5805ad6142fdb05c58595cff19cb2e98cc58a91f55b%40%3Cgitbox.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rd75600cee29cb248d548edcf6338fe296466d63a69e2ed0afc439ec7%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/re1b98da90a5f2e1c2e2d50e31c12e2578d61fe01c0737f9d0bd8de99%40%3Cannounce.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/raea451de09baed76950d6a60cc4bb1b74476c505e03205a3c68c9808%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rffa5cd05d01c4c9853b17f3004d80ea6eb8856c422a8545c5f79b1a6%40%3Ccommits.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rd05b1c9d61dbd220664d559aa0e2b55e5830f006a09e82057f3f7863%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r110cacfa754471361234965ffe851a046e302ff2693b055f49f47b02%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r3341d96d8f956e878fb7b463b08d57ca1d58fec9c970aee929b58e0d%40%3Cissues.activemq.apache.org%3E"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/03/msg00005.html"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210304-0008/"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/activemq","events":[{"introduced":"5f0d6943cb97b0570bf8d58e8eaf9f0003a5cb6c"},{"fixed":"a0d4141a00ba5de4afaee160836898b41eb28065"},{"introduced":"86dd78b1aa64cbf0af15669c0e4af62dfae0d158"},{"fixed":"e432a78c19e9c30b5afd84e591a428734ad55431"}],"database_specific":{"versions":[{"introduced":"5.15.0"},{"fixed":"5.15.14"},{"introduced":"5.16.0"},{"fixed":"5.16.1"}]}},{"type":"GIT","repo":"https://github.com/apache/activemq-artemis","events":[{"introduced":"0"},{"fixed":"9768017530fdbbefd7c112b55702b5a16b3f058e"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"2.16.0"}]}}],"versions":["1.0.0","1.1.0","1.2.0","1.3.0","1.4.0","1.5.0","1.5.1","2.0.0","2.1.0","2.10.0","2.10.1","2.11.0","2.12.0","2.13.0","2.14.0","2.15.0","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.7.0","2.8.0","2.8.1","2.9.0","activemq-5.15.0","activemq-5.15.1","activemq-5.15.10","activemq-5.15.11","activemq-5.15.12","activemq-5.15.13","activemq-5.15.2","activemq-5.15.3","activemq-5.15.4","activemq-5.15.5","activemq-5.15.6","activemq-5.15.7","activemq-5.15.8","activemq-5.15.9","activemq-5.16.0"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"8.2.0"},{"last_affected":"8.2.4.0"}]},{"events":[{"introduced":"8.2.0"},{"last_affected":"8.2.2"}]},{"events":[{"introduced":"8.0.0"},{"last_affected":"8.2.2"}]},{"events":[{"introduced":"0"},{"last_affected":"12.0.0"}]},{"events":[{"introduced":"0"},{"last_affected":"12.1.0"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-26117.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}