RHSA-2023:3223HighCVSS 8.8

Red Hat Security Advisory: Red Hat AMQ Streams 2.4.0 release and security update

Published
May 18, 2023
Last Modified
August 7, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2020-36518 — jackson-databind: denial of service via a large depth of nested objects CVE-2021-0341 — okhttp: information disclosure via improperly used cryptographic function CVE-2021-37136 — netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data CVE-2021-37137 — netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way CVE-2021-46877 — jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode CVE-2022-24823 — netty: world readable temporary file containing sensitive data CVE-2022-36944 — scala: deserialization gadget chain CVE-2022-40149 — jettison: parser crash by stackoverflow CVE-2022-40150 — jettison: memory exhaustion via user-supplied XML or JSON data CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays CVE-2023-0833 — Streams: component version with information disclosure flaw CVE-2023-1370 — json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) CVE-2023-25194 — kafka: RCE/DoS via SASL JAAS JndiLoginModule configuration in Kafka Connect

🎯 Affected products1

  • Red Hat AMQ Streams 2.4.0

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user. Workaround: Users of Scala's LazyList should never permit deserialization of untrusted data.

🔗 References (19)