Red Hat Security Advisory: AMQ Online 1.5.2 release and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2020-13692 — postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML CVE-2020-14319 — amq-on: CSRF (in graphQL requests) CVE-2020-14348 — AMQ: Denial of Service via unrecognized field injection
🎯 Affected products1
- Red Hat AMQ Online 1.5.2 GA
✅ Remediation
The Red Hat OpenShift Container Platform 3.11 and 4.4/4.5 container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available from https://access.redhat.com. Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally. Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: The user can work around the issue by repairing the resource and removing the invalid (top-level) field.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2020:3209
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.online&version=1.5.2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_amq/7.7/html/release_notes_for_amq_online_1.5_on_openshift/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1852985
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1854373
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3209.json