CVE-2023-4066: Operator: passwords defined in secrets shown in statefulset yaml
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
Other sources
The passwords stored in a secret security-properties-prop-module defined in ActivemqArtemisSecurity CR are shown in StatefulSet details yaml of AMQ Broker.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4066?
CVE-2023-4066 is a vulnerability found in Red Hat's AMQ Broker that stores certain passwords in plaintext in the StatefulSet details yaml.
How does CVE-2023-4066 affect Red Hat's AMQ Broker Operator?
Red Hat's AMQ Broker Operator version 7.11.1 is affected by CVE-2023-4066.
How can I fix CVE-2023-4066?
To fix CVE-2023-4066, upgrade to AMQ Broker Operator version 7.11.1.
What is the severity of CVE-2023-4066?
CVE-2023-4066 has a severity level of medium.
Where can I find more information about CVE-2023-4066?
You can find more information about CVE-2023-4066 on the Red Hat security advisory page and the associated bugzilla report.