Red Hat Security Advisory: Red Hat AMQ Broker 7.9.0 release and security update
🔗 CVE IDs covered (15)
📋 Description
CVE-2020-13956 — apache-httpclient: incorrect handling of malformed authority component in request URIs CVE-2020-27223 — jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS CVE-2021-3425 — Broker: discloses JDBC username and password in the application log file CVE-2021-3763 — 7: Incorrect privilege in Management Console CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-21290 — netty: Information disclosure via the local system temporary directory CVE-2021-21295 — netty: possible request smuggling in HTTP/2 due missing validation CVE-2021-21409 — netty: Request smuggling via content-length header CVE-2021-28163 — jetty: Symlink directory exposes webapp directory contents CVE-2021-28164 — jetty: Ambiguous paths can access WEB-INF CVE-2021-28165 — jetty: Resource exhaustion when receiving an invalid large TLS frame CVE-2021-28169 — jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory CVE-2021-29425 — apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 CVE-2021-34428 — jetty: SessionListener can prevent a session from being invalidated breaking logout CVE-2021-34429 — jetty: crafted URIs allow bypassing security constraints
🎯 Affected products1
- Red Hat AMQ 7.9.0
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Applications should catch all Throwables within their SessionListener#sessionDestroyed() implementations.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2021:3700
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.9.0
- externalhttps://access.redhat.com/documentation/en-us/red_hat_amq/2021.q4
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1886587
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1927028
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1934116
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1935927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1936629
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1937364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945710
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945712
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945714
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1948752
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971016
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1974891
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1985223
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2000654
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3700.json