RHSA-2021:3225MediumCVSS 7.6

Red Hat Security Advisory: Red Hat AMQ Streams 1.8.0 release and security update

Published
August 19, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2017-18640 — snakeyaml: Billion laughs attack via alias feature CVE-2021-21290 — netty: Information disclosure via the local system temporary directory CVE-2021-21295 — netty: possible request smuggling in HTTP/2 due missing validation CVE-2021-21409 — netty: Request smuggling via content-length header CVE-2021-27568 — json-smart: uncaught exception may lead to crash or information disclosure CVE-2021-28163 — jetty: Symlink directory exposes webapp directory contents CVE-2021-28164 — jetty: Ambiguous paths can access WEB-INF CVE-2021-28165 — jetty: Resource exhaustion when receiving an invalid large TLS frame CVE-2021-28168 — jersey: Local information disclosure via system temporary directory CVE-2021-28169 — jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory CVE-2021-29425 — apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 CVE-2021-34428 — jetty: SessionListener can prevent a session from being invalidated breaking logout

🎯 Affected products1

  • Red Hat AMQ Streams 1.8.0

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Applications should catch all Throwables within their SessionListener#sessionDestroyed() implementations.

🔗 References (16)