RHSA-2020:5365MediumCVSS 8.1
Red Hat Security Advisory: Red Hat AMQ Broker 7.8 release and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2015-5183 — Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ CVE-2019-9827 — hawtio: server side request forgery via initial /proxy/ substring of a URI CVE-2020-13932 — activemq: remote XSS in web console diagram plugin CVE-2020-27216 — jetty: local temporary directory hijacking vulnerability CVE-2021-26117 — activemq: LDAP authentication bypass with anonymous bind CVE-2021-26118 — 7: OpenWire can create destinations with an unpriviledged user
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2020:5365
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.8.0
- externalhttps://access.redhat.com/documentation/en-us/red_hat_amq/2020.q4/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1249182
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1728604
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1858946
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891132
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_5365.json