Required CVE Record Information
Description
Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restricting log access to only trusted users. Users are recommended to upgrade to version 2.40.0, which fixes the issue.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
6.8 | MEDIUM | 4.0 | CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Credits
- Rafael Yanez Illescas <ryanezil@redhat.com> finder
References 1 Total
- https://lists.apache.org/thread/25p96cvzl1mkt29lwm2d8knklkoqolps vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.