activemq-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Claus Ibsen (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (AMQ-4567) JMX operations on broker bypass authorization plugin
Date Wed, 30 Oct 2013 09:48:26 GMT

    [ https://issues.apache.org/jira/browse/AMQ-4567?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13808899#comment-13808899
] 

Claus Ibsen commented on AMQ-4567:
----------------------------------

Dejan is there more work on this? Seems like your solutions is securing the JMX operations
in acceptable way.

>  JMX operations on broker bypass authorization plugin
> -----------------------------------------------------
>
>                 Key: AMQ-4567
>                 URL: https://issues.apache.org/jira/browse/AMQ-4567
>             Project: ActiveMQ
>          Issue Type: Bug
>          Components: Broker
>    Affects Versions: 5.8.0
>            Reporter: Torsten Mielke
>              Labels: authorization
>             Fix For: 5.9.0
>
>
> When securing the broker using authentication and authorization, any JMX operations on
the broker completely bypass the authorization plugin.
> So anyone can modify the broker bypassing the security checks. Also, because of this
its not possible to define a read only user for the web console.



--
This message was sent by Atlassian JIRA
(v6.1#6144)

Mime
View raw message