Use of Weak Credentials in activemq-artemis-operator - CVE-2025-4057
Published: July 7, 2025
Vulnerability identifier: #VU112438
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-4057
CWE-ID: CWE-1391
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to gain unauthorized access to the application.
The vulnerability exists due to the application does not regenerate password between separated CR dependencies. A remote attacker with knowledge of an old passwords or with the ability t guess one can gain unauthorized access to the application.
Affected software
activemq-artemis-operator
AMQ Broker
AMQ Broker
How to mitigate CVE-2025-4057
Install updates from vendor's website.
AMQ Broker - addressed in versions 7.12.5, 7.13.0