
MAL-011 : Une mauvaise configuration de Log4J permet l'injection de JavaScript malveillant dans Red Hat AMQ
The Log4J component of the Redhat A-MQ application is misconfigured to allow the execution of arbitrary “Script” attributes in the Log4J config. If an attacker finds a way to modify the Log4J config used by A-MQ (e.g. via “setConfigText”), the insertion of malicious JavaScript scripts that will result in Remote Code Execution (RCE).
Remarque : Pour exploiter Red Hat AMQ versions > 7.10.2 et < 7.12, reportez-vous à CVE-2023-50780: MBeans dangereux accessibles via l'API Jolokia dans Apache ActiveMQ Artemis.
Le fournisseur ne s'en souciait pas ¯\_(ツ)_/¯.
Cette vulnérabilité nécessite :
Remarque : Si le serveur est configuré avec "--allow-anonymous", alors toute combinaison utilisateur-mot de passe non nulle peut être utilisée pour s'authentifier.
Plus de détails et le processus d'exploitation sont disponibles dans ce PDF.