CVE-2024-8689Medium

CVE-2024-8689 ActiveMQ Content Pack: Cleartext Exposure of Credentials

Published
September 11, 2024
Last Modified
September 11, 2024

🔗 CVE IDs covered (1)

📋 Description

A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles.

🎯 Affected products1

  • ActiveMQ Content Pack

✅ Remediation

This issue is fixed in ActiveMQ Content Pack 1.1.15 and all later versions. You can download the content pack from https://cortex.marketplace.pan.dev/marketplace/details/ActiveMQ/. You should use new ActiveMQ credentials for ActiveMQ integration only after you upgrade it to a fixed version. You should also revoke the previously existing credentials to prevent the misuse of exposed credentials.

🔗 References (1)