Uploaded image for project: 'ServiceMix'
  1. ServiceMix
  2. SM-1925

Add security check on remote broker when using JMSFlow/JCAFlow

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 3.2.3, 3.3.1
    • 3.2.4, 3.3.2
    • servicemix-core
    • None

    Description

      SecuredBroker checks security AFTER a component is invoked, which works fine when the consumer and components are on the same broker. If a consumer is on brokerA and a provider endpoint is on brokerB using JMSFlow it is possible to bypass security and invoke the endpoint on brokerB even if it is using SecuredBroker.

      Attachments

        Activity

          People

            ccustine Chris Custine
            ccustine Chris Custine
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: