CVE-2022-41678 is a critical remote code execution vulnerability impacting Apache ActiveMQ, allowing an authenticated user to achieve arbitrary code execution via the Jolokia API. This flaw carries a CVSS score of 8.8 (High), indicating that a low-privileged network attacker can fully compromise the system's confidentiality, integrity, and availability. Despite not being in CISA's KEV catalog, its exceptionally high EPSS score of 0.936 and community reports confirm the existence of public proof-of-concept exploit code on platforms like GitHub and Nuclei.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.16.6CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
>= 5.17.0, < 5.17.4CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
>= 0, < 5.16.6CPE match | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.