Password Regeneration Vulnerability in ActiveMQ Artemis by Red Hat
CVE-2025-4057

5.5MEDIUM

What is CVE-2025-4057?

A security issue has been identified in ActiveMQ Artemis where the password generated by the activemq-artemis-operator does not properly regenerate between separate Custom Resource (CR) dependencies. This lack of regeneration can lead to potential security risks, as the static passwords may be leveraged for unauthorized access. It is crucial for users to review their configurations and apply necessary mitigations to secure their deployments against this flaw.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.