¡¾Îó²îͨ¸æ¡¿Apache ActiveMQ NMS AMQP ·´ÐòÁл¯Îó²î(CVE-2025-54539)
Ðû²¼Ê±¼ä 2025-10-17Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Apache ActiveMQ NMS AMQP ·´ÐòÁл¯Îó²î | ||
CVE ID | CVE-2025-54539 | ||
Îó²îÀàÐÍ | ·´ÐòÁл¯Îó²î | ·¢Ã÷ʱ¼ä | 2025-10-17 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache ActiveMQÊÇÒ»¿îÓÉApacheÈí¼þ»ù½ð»á¿ª·¢µÄ¿ªÔ´ÐÂÎÅÖÐÐļþ£¬Ö§³ÖJMS¡¢AMQP¡¢MQTT¡¢STOMPµÈ¶àÖÖÐÂÎÅÐÒé¡£ËüÓÃÓÚ¹¹½¨¸ß¿É¿¿µÄÒì²½ÐÂÎÅת´ïϵͳ£¬ÊµÏÖÓ¦ÓüäµÄ½âñîÓëÒ첽ͨѶ£¬ÆÕ±éÓ¦ÓÃÓÚÆóÒµ¼¶ÐÂÎÅÐÐÁС¢ÂþÑÜʽϵͳÓë΢·þÎñ¼Ü¹¹ÖС£
2025Äê10ÔÂ17ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½Apache ActiveMQ NMS AMQP ClientµÄ·´ÐòÁл¯Îó²î£¬µ±Óë²»ÊÜÐÅÍÐAMQP·þÎñÆ÷½»»¥Ê±£¬¿Í»§¶ËµÄ¶þ½øÖÆ·´ÐòÁл¯¿É±»ÀÄÓ㬹¥»÷Õß¿ÉÄÜÖ´ÐÐí§Òâ´úÂë¡£ËäÔÚ2.1.0ÒýÈëallow/deny°×Ãûµ¥ÒÔÏÞÖÆ·´ÐòÁл¯£¬µ«ÔÚijЩÌõ¼þÏ¿ɱ»Èƹý¡£Îó²îÆÀ·Ö9.8·Ö£¬Îó²î¼¶±ðÑÏÖØ¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://activemq.apache.org/


¾©¹«Íø°²±¸11010802024551ºÅ