Bug 2358637 (CVE-2025-27391) - CVE-2025-27391 org.apache.activemq/artemis-core-client: Apache ActiveMQ Artemis: Passwords leaking from broker properties in the debug log
Summary: CVE-2025-27391 org.apache.activemq/artemis-core-client: Apache ActiveMQ Artem...
Keywords:
Status: NEW
Alias: CVE-2025-27391
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-04-09 15:01 UTC by OSIDB Bzimport
Modified: 2025-09-03 08:28 UTC (History)
55 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-04-09 15:01:13 UTC
Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled.

This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restricting log access to only trusted users.

Users are recommended to upgrade to version 2.40.0, which fixes the issue.


Note You need to log in before you can comment on or make changes to this bug.