CVE-2025-27427
Description
A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesnt have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesnt have permission to change the routing-type of the address.This issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.0.Users are recommended to upgrade to version 2.40.0 which fixes the issue.
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2025-27427 are fixed in Apache-artemis-server 2.40.0 | Windows |
| Vulnerabilities CVE-2025-27427 are fixed in Apache-artemis-server for Linux 2.40.0 | Linux |
| Incorrect Authorization Vulnerability (CVE-2025-27427) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234