CVE-2023-4066
27.09.2023, 21:15
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | openshift_container_platform | 4.11 |
redhat | openshift_container_platform | 4.12 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-313 - Cleartext Storage in a File or on DiskThe application stores sensitive information in cleartext in a file, or on disk.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
References