CVE-2023-4065
published 2023-09-27CVE-2023-4065: A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.23%
13.9th percentile
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_a-mq | — | — |
| redhat | jboss_middleware | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Operator: plaintext password in operator log
vendor_redhat·2023-08-23·CVSS 5.5
CVE-2023-4065 [MEDIUM] CWE-117 Operator: plaintext password in operator log
Operator: plaintext password in operator log
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
Package: amq-broker-operator-container (Red Hat AMQ Broker 7) - Affected
GHSA
GHSA-hhw6-q999-wqqq: A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operat
ghsa_unreviewed·2023-09-27
CVE-2023-4065 [MEDIUM] CWE-117 GHSA-hhw6-q999-wqqq: A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operat
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:4720https://access.redhat.com/security/cve/CVE-2023-4065https://bugzilla.redhat.com/show_bug.cgi?id=2224630https://access.redhat.com/errata/RHSA-2023:4720https://access.redhat.com/security/cve/CVE-2023-4065https://bugzilla.redhat.com/show_bug.cgi?id=2224630
2023-09-27
Published