Red Hat Security Advisory: Red Hat AMQ Broker 7.8.2 release and security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2020-27223 — jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS CVE-2021-3425 — Broker: discloses JDBC username and password in the application log file CVE-2021-21290 — netty: Information disclosure via the local system temporary directory CVE-2021-21295 — netty: possible request smuggling in HTTP/2 due missing validation CVE-2021-21409 — netty: Request smuggling via content-length header CVE-2021-28163 — jetty: Symlink directory exposes webapp directory contents CVE-2021-28164 — jetty: Ambiguous paths can access WEB-INF CVE-2021-28165 — jetty: Resource exhaustion when receiving an invalid large TLS frame
🎯 Affected products1
- Red Hat AMQ 7.8.2
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2021:2689
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.8.2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_amq/2020.q4/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1927028
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1934116
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1936629
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1937364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945710
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945712
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945714
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2689.json