
MAL-011: Log4J Misconfiguration Allows Malicious JavaScript in Red Hat AMQ
The Log4J component of the Redhat A-MQ application is misconfigured to allow the execution of arbitrary “Script” attributes in the Log4J config. If an attacker finds a way to modify the Log4J config used by A-MQ (e.g. via “setConfigText”), the insertion of malicious JavaScript scripts that will result in Remote Code Execution (RCE).
Remarque : Pour exploiter Red Hat AMQ versions > 7.10.2 et < 7.12, reportez-vous à CVE-2023-50780: MBeans dangereux accessibles via l'API Jolokia dans Apache ActiveMQ Artemis.
Le fournisseur ne s'en souciait pas ¯\_(ツ)_/¯.
Cette vulnérabilité nécessite :
Remarque : Si le serveur est configuré avec "--allow-anonymous", alors toute combinaison utilisateur-mot de passe non nulle peut être utilisée pour s'authentifier.
Plus de détails et le processus d'exploitation sont disponibles dans ce PDF.
Code pour exploiter Log4J via Jolokia (a.k.a log4jolokia)
CVE-2023-50780: MBeans dangereux accessibles via l'API Jolokia dans Apache ActiveMQ Artemis