A flaw was found in Red Hats AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
The product stores sensitive information in cleartext in a file, or on disk.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jboss_a-mq | Redhat | 7 (including) | 7 (including) |
Jboss_middleware | Redhat | 1 (including) | 1 (including) |
RHEL-8 based Middleware Containers | RedHat | amq7/amq-broker-rhel8-operator:7.11.1-9 | * |
RHEL-8 based Middleware Containers | RedHat | amq7/amq-broker-rhel8-operator-bundle:7.11.1-12 | * |