CVE-2025-4057
Moderate
ActiveMQ Artemis AMQ Broker Operator Starting Credentials Reuse in github.com/arkmq-org/activemq-artemis-operator
ActiveMQ Artemis AMQ Broker Operator Starting Credentials Reuse in github.com/arkmq-org/activemq-artemis-operator
Exploit probability
0.2%
Published
May 29, 2025
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
70 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2025-4057
View original source
A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between separated CR dependencies.
Open Source Vulnerabilities
GO-2025-3717
View original source
ActiveMQ Artemis AMQ Broker Operator Starting Credentials Reuse in github.com/arkmq-org/activemq-artemis-operator
Open Source Vulnerabilities
GHSA-q5q7-8x6x-hcg2
View original source
A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between separated CR dependencies.
05 / REFERENCES
Further evidence
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2025:12355
- https://access.redhat.com/errata/RHSA-2025:12473
- https://access.redhat.com/errata/RHSA-2025:8147
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html
- https://access.redhat.com/security/cve/CVE-2025-4057
- https://bugzilla.redhat.com/show_bug.cgi?id=2362827
- https://catalog.redhat.com/software/containers/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4057.json
- https://github.com/arkmq-org/activemq-artemis-operator
- https://github.com/arkmq-org/activemq-artemis-operator/commit/d3482fab6d0060794226c9e5a6fa67d209abc35a
- https://github.com/arkmq-org/activemq-artemis-operator/issues/1130
- https://nvd.nist.gov/vuln/detail/CVE-2025-4057
- https://github.com/advisories/GHSA-q5q7-8x6x-hcg2