Skip to main content

Cleartext Storage of Sensitive Information

CVE-2024-8689

Severity Medium
Score 6/10

Summary

A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles.

  • HIGH
  • NETWORK
  • PASSIVE
  • NONE

CWE-312 - Cleartext Storage of Sensitive Information

The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

References

Advisory Timeline

  • Published