activemq-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Torsten Mielke (JIRA)" <j...@apache.org>
Subject [jira] [Created] (AMQ-4567) JMX operations on broker bypass authorization plugin
Date Mon, 03 Jun 2013 10:24:20 GMT
Torsten Mielke created AMQ-4567:
-----------------------------------

             Summary:  JMX operations on broker bypass authorization plugin
                 Key: AMQ-4567
                 URL: https://issues.apache.org/jira/browse/AMQ-4567
             Project: ActiveMQ
          Issue Type: Bug
          Components: Broker
    Affects Versions: 5.8.0
            Reporter: Torsten Mielke


When securing the broker using authentication and authorization, any JMX operations on the
broker completely bypass the authorization plugin.
So anyone can modify the broker bypassing the security checks. Also, because of this its not
possible to define a read only user for the web console.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira

Mime
View raw message