CVE-2023-4066
published 2023-09-27CVE-2023-4066: A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.15%
4.7th percentile
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_a-mq | — | — |
| redhat | jboss_middleware | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pp2q-hf69-vw5g: A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecuri
ghsa_unreviewed·2023-09-27
CVE-2023-4066 [MEDIUM] CWE-312 GHSA-pp2q-hf69-vw5g: A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecuri
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
Red Hat
Operator: Passwords defined in secrets shown in StatefulSet yaml
vendor_redhat·2023-08-23·CVSS 5.5
CVE-2023-4066 [MEDIUM] CWE-313 Operator: Passwords defined in secrets shown in StatefulSet yaml
Operator: Passwords defined in secrets shown in StatefulSet yaml
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
Package: activemq-broker-operator (Red Hat AMQ Broker 7) - Affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:4720https://access.redhat.com/security/cve/CVE-2023-4066https://bugzilla.redhat.com/show_bug.cgi?id=2224677https://access.redhat.com/errata/RHSA-2023:4720https://access.redhat.com/security/cve/CVE-2023-4066https://bugzilla.redhat.com/show_bug.cgi?id=2224677
2023-09-27
Published