Detection, Exploit and Mitigation for CVE 2023 46604. # CVE-2023-46604 – Apache ActiveMQ RCE (OpenWire Protocol)
This repository documents a lab environment used to understand and detect the CVE-2023-46604 vulnerability affecting Apache ActiveMQ.
The goal of this project:
- Understand how the exploit behaves at the protocol level
- Capture malicious OpenWire traffic
- Build detection rules using Suricata
- Document steps for educational and defensive security use
> ⚠️ **Important**: This repository is for educational and defensive security purposes.
> No exploit code is included here. Only lab setup, detection, and mitigation steps.
## Contents
- Lab network topology
- ActiveMQ installation notes
- Wireshark detection steps
- Suricata IDS rule and configuration
- Screenshots (redacted and safe to share)
- Analysis notes
[4.0K] /data/pocs/00639f7e9e096890d353190808204aeae112b619
├── [4.0K] docs
│ └── [ 514] lab-steps.md
├── [4.0K] mitigation-suricata
│ └── [ 113] local.rules
└── [ 810] README.md
3 directories, 3 files