Re: Artemis security plugin doesn't allow to change clientId

2022-04-11 Thread Justin Bertram
I'm struggling to reproduce the NPE. I pulled down Kapua, switched to your branch (i.e. upgrade-artemis-2_21), configured Docker, etc., but I get this error when I run RunDeviceBrokerI9nTest: ERROR o.e.k.q.i.steps.DockerSteps - Error while starting base docker environment: Image not found: kapua

Re: ServerSession username vs validateduser

2022-04-11 Thread Aaron Hoffer
The ticket and PR are up. https://issues.apache.org/jira/browse/ARTEMIS-3765 https://github.com/apache/activemq-artemis/pull/4019 On Tue, Apr 5, 2022 at 9:41 AM Justin Bertram wrote: > Awesome! I had planned on implementing this at some point, but I hadn't had > the chance yet. It should be pre

R: Artemis security plugin doesn't allow to change clientId

2022-04-11 Thread Modanese, Riccardo
Hi Justin, I created a small test (using Paho client) and I confirm the null pointer while a “regular” stealing link happens (with Kapua security and server plugins configured) ERROR [org.apache.activemq.artemis.core.protocol.mqtt] AMQ834002: Error processing control packet: MqttConnectMessage

Re: Critical : CVE-2022-22965 : SpringShell Vulnerability affecting Apache-tomcat

2022-04-11 Thread Matt Pavlovich
Hello Aditya- ActiveMQ is not vulnerable— the current exploits require spring web components, be running in Tomcat as a war and using JDK 9+. Which security scanner are you using? It sounds like it is over zealous in identifying problematic instances. Thanks, Matt Pavlovich > On Apr 11, 2022

Critical : CVE-2022-22965 : SpringShell Vulnerability affecting Apache-tomcat

2022-04-11 Thread Aditya Nautiyal
Hi Team, Our scanners are started complaining about SpringShell Critical issues under /opt/apache-activemq* as shown below : [cid:image001.png@01D84DA6.9A9C6400] We recently upgraded our systems to 5.16.4, can you please advise what is the plan to remediate this from ActiveMQ side on this. [cid