Vulnerability Details CVE-2020-10727
A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use this flaw to read the contents of the Artemis shadow file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.5%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 2.1
Products affected by CVE-2020-10727
-
cpe:2.3:a:apache:activemq_artemis:2.10.0
-
cpe:2.3:a:apache:activemq_artemis:2.10.1
-
cpe:2.3:a:apache:activemq_artemis:2.11.0
-
cpe:2.3:a:apache:activemq_artemis:2.12.0
-
cpe:2.3:a:apache:activemq_artemis:2.7.0
-
cpe:2.3:a:apache:activemq_artemis:2.8.0
-
cpe:2.3:a:apache:activemq_artemis:2.8.1
-
cpe:2.3:a:apache:activemq_artemis:2.9.0
-
cpe:2.3:a:netapp:oncommand_workflow_automation:-