[ https://issues.apache.org/jira/browse/AMQ-4567?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13808899#comment-13808899 ]
Claus Ibsen commented on AMQ-4567: ---------------------------------- Dejan is there more work on this? Seems like your solutions is securing the JMX operations in acceptable way. > JMX operations on broker bypass authorization plugin > ----------------------------------------------------- > > Key: AMQ-4567 > URL: https://issues.apache.org/jira/browse/AMQ-4567 > Project: ActiveMQ > Issue Type: Bug > Components: Broker > Affects Versions: 5.8.0 > Reporter: Torsten Mielke > Labels: authorization > Fix For: 5.9.0 > > > When securing the broker using authentication and authorization, any JMX > operations on the broker completely bypass the authorization plugin. > So anyone can modify the broker bypassing the security checks. Also, because > of this its not possible to define a read only user for the web console. -- This message was sent by Atlassian JIRA (v6.1#6144)