An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2.
Unsafe processing (parsing) of OpenMQ configuration does not properly validate file access paths, which is a classic case of a path traversal vulnerability (CWE-22). An attacker can prepare an appropriate network request and force the broker to read files outside the allowed directory. Due to the lack of authentication requirement (PR:N, UI:N), the attack can be carried out directly over the network without any user interaction.
An attacker can read arbitrary files from the operating system of the host running the OpenMQ broker, including potentially sensitive configuration data, keys, passwords and other confidential information. In specific scenarios, the vulnerability can be exploited for remote code execution (RCE) on the broker server.
Patches available from the vendor should be applied according to the references (https://gitlab.eclipse.org/security/cve-assignment/-/issues/84). Until the patch is deployed, it is recommended to restrict network access to the OpenMQ broker port exclusively to trusted hosts using a firewall and to monitor unauthorized access attempts.
Eclipse OpenMQ — versions indicated in the vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HEclipse Openmq
APPEclipse≤ 6.5.1
Related vulnerabilities
Eclipse OpenMQ — domyślne dane logowania umożliwiają przejęcie kontroli
Eclipse GlassFish: CSRF+SSRF w DownloadServlet umożliwia przejęcie domeny
Eclipse Milo: padding oracle w uwierzytelnianiu OPC-UA umożliwia odzyskanie hasła
RCE w konsoli administracyjnej Eclipse GlassFish
RCE poprzez wstrzyknięcie Expression Language w Eclipse GlassFish