SCA: security update for org.apache.activemq:artemis-server (GHSA-3w85-5p9g-h334)

low Tenable Self-Hosted Container Security Plugin ID 423602

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or
createNonDurableQueue permission on an address can augment the routing-type supported by that address even
if said user doesn't have the createAddress permission for that particular address. When combined with the
send permission and automatic queue creation a user could successfully send a message with a routing-type
not supported by the address when that message should actually be rejected on the basis that the user
doesn't have permission to change the routing-type of the address. This issue affects Apache ActiveMQ
Artemis from 2.0.0 through 2.39.0. Users are recommended to upgrade to version 2.40.0 which fixes the
issue. (CVE-2025-27427)

See Also

https://github.com/advisories/GHSA-3w85-5p9g-h334

Plugin Details

Severity: Low

ID: 423602

Version: Revision 1.13

Type: Local

Family: SCA Checks

Published: 4/1/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2025-27427

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Low

Base Score: 2.3

Threat Score: 0.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/1/2025

Vulnerability Publication Date: 4/1/2025

Reference Information

CVE: CVE-2025-27427

cwe: CWE-863