Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-27391

ActiveMQ Artemis: broker property values, passwords included, written to the debug log

Technology

ActiveMQ Artemis

CVSS Score

6.5 / 10.0

Affected Versions

ActiveMQ Artemis 1.5.1 to 2.39.0

Upstream Fix

2.40.0

Published

April 9, 2025

OSSeva Coverage

Fixed upstream

Description

When the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger is set to debug, the broker logs the value of every broker property, including passwords. The advisory's mitigation is to restrict log access to trusted users. Apache rates it moderate.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running ActiveMQ Artemis 1.5.1 to 2.39.0, you need this patch. Book a discovery call to get covered.