Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restricting log access to only trusted users. Users are recommended to upgrade to version 2.40.0, which fixes the issue.
History

Thu, 10 Apr 2025 14:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Wed, 09 Apr 2025 17:45:00 +0000

Type Values Removed Values Added
References

Wed, 09 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restricting log access to only trusted users. Users are recommended to upgrade to version 2.40.0, which fixes the issue.
Title Apache ActiveMQ Artemis: Passwords leaking from broker properties in the debug log
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-04-09T17:02:46.727Z

Reserved: 2025-02-24T09:38:34.333Z

Link: CVE-2025-27391

cve-icon Vulnrichment

Updated: 2025-04-09T17:02:46.727Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-09T15:16:02.090

Modified: 2025-04-09T20:02:41.860

Link: CVE-2025-27391

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-04-09T14:42:32Z

Links: CVE-2025-27391 - Bugzilla