Vulnerability: Passwords Exposed in Plaintext in AMQ Broker StatefulSet Details YAML

Vulnerability: Passwords Exposed in Plaintext in AMQ Broker StatefulSet Details YAML

CVE-2023-4066 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.

Learn more about our Web Application Penetration Testing UK.