CVE-2025-27533: Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation

2025-05-06 Thread Christopher L. Shannon
Affected versions: - Apache ActiveMQ 6.0.0 before 6.1.6 - Apache ActiveMQ 5.18.0 before 5.18.7 - Apache ActiveMQ 5.17.0 before 5.17.7 - Apache ActiveMQ 5.16.0 before 5.16.8 Description: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWir

Connection router for filtering certificate based users

2025-05-06 Thread Shiv Kumar Dixit
Hi Domenico I am exploring how to restrict users (specially certificate based) for connecting based on certain conditions. I came across https://lists.apache.org/thread/not2kzq23vx60zjvsl9ffrx7rfps6wzs. I tried to use USER_NAME key for filtering and it worked fine for basic authentication users