RHSA-2022:0219MediumCVSS 5.9

Red Hat Security Advisory: Red Hat AMQ Streams 1.6.6 release and security update

Published
January 20, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2021-38153 — Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients CVE-2021-45105 — log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern

🎯 Affected products1

  • Red Hat AMQ Streams 1.6.6

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: For Log4j 2 versions up to and including 2.16.0, this flaw can be mitigated by: - In PatternLayout in the Log4j logging configuration, replace Context Lookups like ${ctx:loginId} or $${ctx:loginId} with Thread Context Map patterns (%X, %mdc, or %MDC) like %X{loginId}. - Otherwise, in the Log4j logging configuration, remove references to Context Lookups like ${ctx:loginId} or $${ctx:loginId} where they originate from sources external to the application such as HTTP headers or user input.

🔗 References (6)