5.5
CVE-2023-4065
- EPSS 0.23%
- Veröffentlicht 27.09.2023 15:19:39
- Zuletzt bearbeitet 21.11.2024 08:34:19
- Erkennungen
Operator: plaintext password in operator log
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Jboss A-mq Version 7
Redhat ≫ Jboss Middleware Version 1
Redhat ≫ Openshift Container Platform Version 4.11
Redhat ≫ Openshift Container Platform Version 4.12
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.136 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| RedHat | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-117 Improper Output Neutralization for Logs
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
https://access.redhat.com/errata/RHSA-2023:4720
https://access.redhat.com/security/cve/CVE-2023-4065
https://bugzilla.redhat.com/show_bug.cgi?id=2224630