RHSA-2020:2751HighCVSS 9.0

Red Hat Security Advisory: Red Hat AMQ Broker 7.7 release and security update

Published
June 25, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2020-1953 — apache-commons-configuration: uncontrolled class instantiation when loading YAML files CVE-2020-10727 — broker: resetUsers operation stores password in plain text CVE-2020-11612 — netty: compression/decompression codecs don't enforce limits on buffer allocation sizes

🎯 Affected products1

  • Red Hat AMQ

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: There is currently no mitigation available for this vulnerability. Workaround: When resetting a user an alternative is to use the broker instance CLI `/bin/artemis user reset` which is not affected by the flaw

🔗 References (8)