Red Hat Security Advisory: Red Hat AMQ Broker 7.10.0 release and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2019-10744 — nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties CVE-2020-36518 — jackson-databind: denial of service via a large depth of nested objects CVE-2021-4040 — Broker: Malformed message can result in partial DoS (OOM) CVE-2021-43797 — netty: control chars in header names may lead to HTTP request smuggling CVE-2022-1833 — amq: AMQ Broker Operator ClusterWide Edit Permissions Due Token Exposure CVE-2022-22968 — Framework: Data Binding Rules Vulnerability CVE-2022-23913 — artemis-commons: Apache ActiveMQ Artemis DoS
🎯 Affected products1
- Red Hat AMQ 7.10.0
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: In order to have these privileges correctly set in this version, opt for using the CLI method at https://access.redhat.com/documentation/en-us/red_hat_amq/7.4/html/deploying_amq_broker_on_openshift_container_platform/broker-operator-broker-ocp#operator-install-broker-ocp Make sure to use the latest available version in order to have access to the latest bug and security fixes.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2022:5101
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.10.0
- externalhttps://access.redhat.com/documentation/en-us/red_hat_amq_broker/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1739497
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2028254
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031958
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2063601
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064698
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075441
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089406
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_5101.json