Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled.
This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restricting log access to only trusted users.
Users are recommended to upgrade to version 2.40.0, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Apr 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Wed, 09 Apr 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 09 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 09 Apr 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restricting log access to only trusted users. Users are recommended to upgrade to version 2.40.0, which fixes the issue. | |
Title | Apache ActiveMQ Artemis: Passwords leaking from broker properties in the debug log | |
Weaknesses | CWE-532 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-09T17:02:46.727Z
Reserved: 2025-02-24T09:38:34.333Z
Link: CVE-2025-27391

Updated: 2025-04-09T17:02:46.727Z

Status : Awaiting Analysis
Published: 2025-04-09T15:16:02.090
Modified: 2025-04-09T20:02:41.860
Link: CVE-2025-27391
