Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2025-27391
ActiveMQ Artemis: broker property values, passwords included, written to the debug log
Technology
ActiveMQ Artemis
CVSS Score
6.5 / 10.0
Affected Versions
ActiveMQ Artemis 1.5.1 to 2.39.0
Upstream Fix
2.40.0
Published
April 9, 2025
OSSeva Coverage
Fixed upstream
Description
When the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger is set to debug, the broker logs the value of every broker property, including passwords. The advisory's mitigation is to restrict log access to trusted users. Apache rates it moderate.
Is your ActiveMQ Artemis deployment affected?
If you're running ActiveMQ Artemis 1.5.1 to 2.39.0, you need this patch. Book a discovery call to get covered.