{"id":"CVE-2020-10727","aliases":["GHSA-q9g8-9hpp-xc82"],"url":"https://o3.security/vulnerability/CVE-2020-10727","summary":"ActiveMQ Artemis has Insufficiently Protected Credentials","details":"A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use this flaw to read the contents of the Artemis shadow file.","published":"2020-06-26T16:15:12.063Z","modified":"2026-07-08T20:03:55.594458Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.activemq:artemis-commons","fixedVersion":"2.13.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210827-0001/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1827200"},{"type":"REPORT","url":"https://issues.redhat.com/browse/ENTMQBR-3435"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:03:55.594458Z"}}