CVE-2023-4066: Red Hat JBoss A-Mq

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.

Affected products

  • Red Hat JBoss A-Mq: version 7 only
  • Red Hat JBoss Middleware: version 1 only
  • Red Hat Openshift Container Platform: version 4.11 only; version 4.12 only

Published 2023-09-27. Last modified 2026-06-17.