5.5

CVE-2023-4066

Operator: passwords defined in secrets shown in statefulset yaml

A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Jboss A-mq Version 7
Redhat ≫ Jboss Middleware Version 1
Redhat ≫ Openshift Container Platform Version 4.11
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform Version 4.12
   Redhat ≫ Enterprise Linux Version 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.046
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
RedHat 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

CWE-313 Cleartext Storage in a File or on Disk

The product stores sensitive information in cleartext in a file, or on disk.

https://access.redhat.com/errata/RHSA-2023:4720
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2023-4066
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2224677
Vendor Advisory
Issue Tracking