RHSA-2022:5101HighCVSS 9.1

Red Hat Security Advisory: Red Hat AMQ Broker 7.10.0 release and security update

Published
June 16, 2022
Last Modified
August 7, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2019-10744 — nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties CVE-2020-36518 — jackson-databind: denial of service via a large depth of nested objects CVE-2021-4040 — Broker: Malformed message can result in partial DoS (OOM) CVE-2021-43797 — netty: control chars in header names may lead to HTTP request smuggling CVE-2022-1833 — amq: AMQ Broker Operator ClusterWide Edit Permissions Due Token Exposure CVE-2022-22968 — Framework: Data Binding Rules Vulnerability CVE-2022-23913 — artemis-commons: Apache ActiveMQ Artemis DoS

🎯 Affected products1

  • Red Hat AMQ 7.10.0

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: In order to have these privileges correctly set in this version, opt for using the CLI method at https://access.redhat.com/documentation/en-us/red_hat_amq/7.4/html/deploying_amq_broker_on_openshift_container_platform/broker-operator-broker-ocp#operator-install-broker-ocp Make sure to use the latest available version in order to have access to the latest bug and security fixes.

🔗 References (12)