{"id":"GHSA-836g-5fr5-fgcr","summary":"Missing Authentication for Critical Function in Apache TomEE","details":"If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 - 8.0.1, Apache TomEE 7.1.0 - 7.1.2, Apache TomEE 7.0.0-M1 - 7.0.7, Apache TomEE 1.0.0 - 1.7.5.","aliases":["CVE-2020-11969"],"modified":"2023-11-08T04:02:07.808393Z","published":"2022-02-10T23:07:37Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-05-12T15:57:39Z","nvd_published_at":"2020-06-15T20:15:00Z","cwe_ids":["CWE-306"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-11969"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r85b87478f8aa4751aa3a06e88622e80ffabae376ee7283e147ee56b9@%3Cdev.tomee.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rbd23418646dedda70a546331ea1c1d115b8975b7e7dc452d10e2e773%40%3Cdev.tomee.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rbd23418646dedda70a546331ea1c1d115b8975b7e7dc452d10e2e773@%3Cannounce.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ref088c4732e1a8dd0bbbb96e13ffafcfe65f984238ffa55f438d78fe@%3Cdev.tomee.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ref088c4732e1a8dd0bbbb96e13ffafcfe65f984238ffa55f438d78fe@%3Cusers.tomee.apache.org%3E"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2020/12/16/2"}],"affected":[{"package":{"name":"org.apache.tomee:tomee","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomee/tomee"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0-M1"},{"fixed":"8.0.2"}]}],"versions":["8.0.0","8.0.0-M1","8.0.0-M2","8.0.0-M3","8.0.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 8.0.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-836g-5fr5-fgcr/GHSA-836g-5fr5-fgcr.json"}},{"package":{"name":"org.apache.tomee:tomee","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomee/tomee"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.1.0"},{"fixed":"7.1.3"}]}],"versions":["7.1.0","7.1.1","7.1.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 7.1.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-836g-5fr5-fgcr/GHSA-836g-5fr5-fgcr.json"}},{"package":{"name":"org.apache.tomee:tomee","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomee/tomee"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0-M1"},{"fixed":"7.0.8"}]}],"versions":["7.0.0","7.0.0-M1","7.0.0-M2","7.0.0-M3","7.0.1","7.0.2","7.0.3","7.0.4","7.0.5","7.0.6","7.0.7"],"database_specific":{"last_known_affected_version_range":"\u003c= 7.0.7","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-836g-5fr5-fgcr/GHSA-836g-5fr5-fgcr.json"}},{"package":{"name":"org.apache.tomee:tomee","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomee/tomee"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.7.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-836g-5fr5-fgcr/GHSA-836g-5fr5-fgcr.json","last_known_affected_version_range":"\u003c= 1.7.5"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}