Use of Weak Credentials in activemq-artemis-operator - CVE-2025-4057

 

Use of Weak Credentials in activemq-artemis-operator - CVE-2025-4057

Published: July 7, 2025


Vulnerability identifier: #VU112438
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-4057
CWE-ID: CWE-1391
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to gain unauthorized access to the application.

The vulnerability exists due to the application does not regenerate password between separated CR dependencies. A remote attacker with knowledge of an old passwords or with the ability t guess one can gain unauthorized access to the application. 


Affected software

activemq-artemis-operator
AMQ Broker

How to mitigate CVE-2025-4057

Install updates from vendor's website.

AMQ Broker - addressed in versions 7.12.5, 7.13.0

External References

Related Security Bulletins