RHSA-2020:0481HighCVSS 7.5
Red Hat Security Advisory: Red Hat JBoss Fuse/A-MQ 6.3 R15 security and bug fix update
🔗 CVE IDs covered (2)
📋 Description
CVE-2015-9251 — jquery: Cross-site scripting via cross-domain ajax requests CVE-2019-10174 — infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods
🎯 Affected products1
- Red Hat Fuse 6.3
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are located in the download section of the customer portal. The References section of this erratum contains a download link (you must log in to download the update). Workaround: There is no known mitigation for this issue.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2020:0481
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.amq.broker&downloadType=securityPatches&version=6.3.0
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=6.3
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_fuse/6.3/html/release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1399546
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1703469
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_0481.json