CVE-2026-101292 Apache ActiveMQ Artemis 不安全反射漏洞
影响认证的攻击者可加载并实例化任意类,导致拒绝服务或状态篡改
Apache ActiveMQ Artemis 2.34.0 之前版本在 FederationStreamConnectMessage.getFederationPolicy() 中存在不安全反射漏洞。该方法直接使用从 CORE 协议报文缓冲区读取的类名调用 Class.forName(clazz).getConstructor().newInstance(),未做类型校验。攻击者可借此加载并实例化 Artemis 模块类加载器可见的任意类。
影响范围
Apache ActiveMQ Artemis 2.34.0 之前的版本。具体受影响版本范围以官方公告为准,暂无更细粒度公开信息。
漏洞详情
漏洞类型为不安全反射(Unsafe Reflection)。成因是 getFederationPolicy() 未验证从 CORE 协议 wire buffer 读取的 clazz 字段,直接用于 Class.forName 并实例化。利用方式是认证的 federation peer 发送携带恶意类名的 FEDERATION_DOWNSTREAM_CONNECT 报文,触发目标类的静态初始化块和无参构造函数执行。
利用条件与风险
利用前提是攻击者需为已认证的 federation peer,可向 broker 发送 CORE 协议报文。实战中可造成系统属性污染、类加载导致内存耗尽或 broker 状态被篡改等拒绝服务后果。
修复建议
官方修复方案为升级至 Apache ActiveMQ Artemis 2.34.0 或更高版本。临时缓解措施包括限制 federation 连接来源、加强认证与网络访问控制,暂无其他公开缓解信息。
Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers () and no-argument constructors (()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.