Metrics
Affected Vendors & Products
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache activemq Artemis |
|
CPEs | cpe:2.3:a:apache:activemq_artemis:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache activemq Artemis |
|
Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 10 Apr 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Wed, 09 Apr 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 09 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 09 Apr 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restricting log access to only trusted users. Users are recommended to upgrade to version 2.40.0, which fixes the issue. | |
Title | Apache ActiveMQ Artemis: Passwords leaking from broker properties in the debug log | |
Weaknesses | CWE-532 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: apache
Published: 2025-04-09T14:42:32.504Z
Updated: 2025-04-09T17:02:46.727Z
Reserved: 2025-02-24T09:38:34.333Z
Link: CVE-2025-27391

Updated: 2025-04-09T17:02:46.727Z

Status : Analyzed
Published: 2025-04-09T15:16:02.090
Modified: 2025-07-14T12:12:22.513
Link: CVE-2025-27391
