A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfile when using the jdbc persistence functionality. Versions shipped in Red Hat AMQ 7 are vulnerable.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1936629 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2021-06-01 13:15
Updated : 2021-06-11 08:18
NVD link : CVE-2021-3425
Mitre link : CVE-2021-3425
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
redhat
- jboss_a-mq