RHSA-2021:2689MediumCVSS 7.5

Red Hat Security Advisory: Red Hat AMQ Broker 7.8.2 release and security update

Published
July 12, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2020-27223 — jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS CVE-2021-3425 — Broker: discloses JDBC username and password in the application log file CVE-2021-21290 — netty: Information disclosure via the local system temporary directory CVE-2021-21295 — netty: possible request smuggling in HTTP/2 due missing validation CVE-2021-21409 — netty: Request smuggling via content-length header CVE-2021-28163 — jetty: Symlink directory exposes webapp directory contents CVE-2021-28164 — jetty: Ambiguous paths can access WEB-INF CVE-2021-28165 — jetty: Resource exhaustion when receiving an invalid large TLS frame

🎯 Affected products1

  • Red Hat AMQ 7.8.2

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).

🔗 References (13)