CVE-2025-4057 Details
Description
A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between separated CR dependencies.
A vulnerability exists in ActiveMQ Artemis within the AMQ Broker Operator. The issue arises because the operator-generated passwords do not refresh between different Custom Resource (CR) dependencies. This flaw affects several starting credentials, including AMQ_PASSWORD, AMQ_USER, AMQ_CLUSTER_PASSWORD, and AMQ_CLUSTER_USER, which fail to regenerate between separate CR instances.
Users can update to the latest AMQ Broker version 7.13.0.OPR.1.GA, which addresses this vulnerability. Instructions for updating can be found in the Red Hat AMQ Broker 7 documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 26, 2025CISA-ADP
Assessed May 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1391 | Use of Weak Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat ActiveMQ Artemis | All versions |
CPE
Remediation
| |
| Red Hat AMQ Broker | < 7.13.0.OPR.1.GA |
CPE
Remediation
| |
| Red Hat activemq-artemis-operator | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jul 31, 2025 | CVE Modified | [email protected] |
| Jul 31, 2025 | CVE Modified | [email protected] |
| Jul 25, 2025 | CVE Modified | [email protected] |
| May 26, 2025 | CVE Modified | [email protected] |
| May 26, 2025 | New CVE Received | [email protected] |
Volerion