#CVE-2023-46604

Vulnerability/Target

2023-11-17 • Andariel 그룹의 Apache ActiveMQ 취약점 (CVE-2023-46604) 공격 정황

The Java OpenWire protocol marshaller is vulnerable to remote code execution. A remote attacker with network access to a Java-based OpenWire broker or client can manipulate serialized class types so that the broker or client instantiates an arbitrary class on its classpath, enabling shell-command execution. Fixed broker and client versions are 5.15.16, 5.16.7, 5.17.6, and 5.18.3.

https://www.cve.org/CVERecord?id=CVE-2023-46604

Tagged Reports

« Back