Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4066

Опубликовано: 23 авг. 2023
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7activemq-broker-operatorAffected
RHEL-8 based Middleware Containersamq7/amq-broker-rhel8-operatorFixedRHSA-2023:472023.08.2023
RHEL-8 based Middleware Containersamq7/amq-broker-rhel8-operator-bundleFixedRHSA-2023:472023.08.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-313
https://bugzilla.redhat.com/show_bug.cgi?id=2224677Operator: Passwords defined in secrets shown in StatefulSet yaml

EPSS

Процентиль: 15%
0.00049
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.

CVSS3: 5.5
github
больше 2 лет назад

A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.

EPSS

Процентиль: 15%
0.00049
Низкий

5.5 Medium

CVSS3