PT-2021-20410 · Red Hat · Red Hat Amq

Jonathan Christison

·

Published

2021-06-01

·

Updated

2021-06-11

·

CVE-2021-3425

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Red Hat AMQ versions 7
Description: A flaw in the AMQ Broker discloses JDBC encrypted usernames and passwords in the application logfile when using the jdbc persistence functionality.
Recommendations: For Red Hat AMQ version 7, update the configuration to exclude sensitive information from the application logfile, or consider disabling the jdbc persistence functionality until a fix is available.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3425

Affected Products

Red Hat Amq