A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jboss_a-mq | Redhat | 7 (including) | 7 (including) |
Jboss_middleware | Redhat | 1 (including) | 1 (including) |
RHEL-8 based Middleware Containers | RedHat | amq7/amq-broker-rhel8-operator:7.11.1-9 | * |
RHEL-8 based Middleware Containers | RedHat | amq7/amq-broker-rhel8-operator-bundle:7.11.1-12 | * |