CVE-2025-27391

Source
https://cve.org/CVERecord?id=CVE-2025-27391
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27391.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-27391
Aliases
Downstream
Published
2025-04-09T14:42:32.504Z
Modified
2026-08-12T03:51:30.050380023Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
Apache ActiveMQ Artemis: Passwords leaking from broker properties in the debug log
Details

Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled.

This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restricting log access to only trusted users.

Users are recommended to upgrade to version 2.40.0, which fixes the issue.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.5.1"
                },
                {
                    "fixed": "2.40.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "1.5.1"
                },
                {
                    "fixed": "2.40.0"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-532"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27391.json"
}
References

Affected packages

Git / github.com/apache/artemis

Affected ranges

Type
GIT
Repo
https://github.com/apache/artemis
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.5.1"
        },
        {
            "fixed": "2.40.0"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*"
}

Affected versions

1.*
1.5.1
2.*
2.0.0
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.25.0
2.26.0
2.27.0
2.28.0
2.29.0
2.3.0
2.30.0
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.34.0
2.35.0
2.36.0
2.37.0
2.38.0
2.39.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.8.1
2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27391.json"