Apache ActiveMQ Artemis
cpe:2.3:a:apache:activemq_artemis:*:*:*:*:*:*:*
- >= 1.5.1, < 2.40.0
A vulnerability allowing the unintentional logging of sensitive information has been identified in Apache ActiveMQ Artemis versions 1.5.1 prior to 2.40.0. When the logger for 'org.apache.activemq.artemis.core.config.impl.ConfigurationImpl' is set to debug level, all broker property values are recorded in the log. This issue can be mitigated by limiting log access to trusted users.
Exposed sensitive information in log files, potentially including passwords.
Users are advised to upgrade to Apache ActiveMQ Artemis version 2.40.0 or later, which addresses this vulnerability. Additionally, log access should be restricted to trusted users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.