{"id":"GHSA-q9g8-9hpp-xc82","summary":"ActiveMQ Artemis has Insufficiently Protected Credentials","details":"A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use this flaw to read the contents of the Artemis shadow file.","aliases":["CVE-2020-10727"],"modified":"2026-07-07T13:15:14.302574199Z","published":"2022-05-24T17:21:42Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-06-24T01:26:20Z","nvd_published_at":"2020-06-26T16:15:00Z","cwe_ids":["CWE-312","CWE-522"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10727"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1827200"},{"type":"PACKAGE","url":"https://github.com/apache/artemis"},{"type":"WEB","url":"https://issues.redhat.com/browse/ENTMQBR-3435"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210827-0001"}],"affected":[{"package":{"name":"org.apache.activemq:artemis-commons","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/artemis-commons"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7.0"},{"fixed":"2.13.0"}]}],"versions":["2.10.0","2.10.1","2.11.0","2.12.0","2.7.0","2.8.0","2.8.1","2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q9g8-9hpp-xc82/GHSA-q9g8-9hpp-xc82.json","last_known_affected_version_range":"\u003c= 2.12.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}