
CVE-2022-41678: Dangerous MBeans Accessible via Jolokia API in Apache ActiveMQ
By listing and inspecting the MBeans exposed by the Jolokia API at http://127.0.0.1:8161/api/jolokia the following attack vectors have been identified:
This vulnerability can be exploited by a local attacker that knows the basic authentication credentials (by default “admin:admin”) used by the ActiveMQ web interface.
The vendor's disclosure for this vulnerability can be found here.
NOTE: This vulnerability is not a "deserialization vulnerability".
This vulnerability requires:
More details and the exploitation process can be found in this PDF.
YouTube presentation on how to exploit Log4J MBeans over JMX/Jolokia (a.k.a. Log4JMX)
Blog post by Y4tacker explaining how to obtain RCE via the Log4J vector.
Proof of concept code by Owen "phith0n" Gong that exploits both the Log4J and JFR vectors.
Blog post by 淚笑 l3yx explaining how to obtain RCE via the Java Flight Recorder.