5.5
CVSSv3

CVE-2020-10727

CVSSv4: NA | CVSSv3: 5.5 | CVSSv2: 2.1 | VMScore: 650 | EPSS: 0.00075 | KEV: Not Included
Published: 26/06/2020 Updated: 21/11/2024

Vulnerability Summary

A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use this flaw to read the contents of the Artemis shadow file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache activemq artemis

netapp oncommand workflow automation -

Vendor Advisories

Synopsis Important: Red Hat AMQ Broker 77 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 77 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sco ...
Synopsis Important: Red Hat AMQ Broker 744 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 744 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability ...