Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
This issue is fixed in ActiveMQ Content Pack 1.1.15 and all later versions. You can download the content pack from https://cortex.marketplace.pan.dev/marketplace/details/ActiveMQ/ . You should use new ActiveMQ credentials for ActiveMQ integration only after you upgrade it to a fixed version. You should also revoke the previously existing credentials to prevent the misuse of exposed credentials.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49348 | A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles. |
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-8689 |
|
Wed, 11 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Sep 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles. | |
| Title | ActiveMQ Content Pack: Cleartext Exposure of Credentials | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-09-11T18:24:17.891Z
Reserved: 2024-09-11T08:21:14.668Z
Link: CVE-2024-8689
Updated: 2024-09-11T18:24:14.316Z
Status : Deferred
Published: 2024-09-11T17:15:14.380
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-8689
No data.
OpenCVE Enrichment
No data.
EUVD