Red Hat Security Advisory: Red Hat AMQ Streams 2.4.0 release and security update
🔗 CVE IDs covered (14)
📋 Description
CVE-2020-36518 — jackson-databind: denial of service via a large depth of nested objects CVE-2021-0341 — okhttp: information disclosure via improperly used cryptographic function CVE-2021-37136 — netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data CVE-2021-37137 — netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way CVE-2021-46877 — jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode CVE-2022-24823 — netty: world readable temporary file containing sensitive data CVE-2022-36944 — scala: deserialization gadget chain CVE-2022-40149 — jettison: parser crash by stackoverflow CVE-2022-40150 — jettison: memory exhaustion via user-supplied XML or JSON data CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays CVE-2023-0833 — Streams: component version with information disclosure flaw CVE-2023-1370 — json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) CVE-2023-25194 — kafka: RCE/DoS via SASL JAAS JndiLoginModule configuration in Kafka Connect
🎯 Affected products1
- Red Hat AMQ Streams 2.4.0
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user. Workaround: Users of Scala's LazyList should never permit deserialization of untrusted data.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2023:3223
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.streams&version=2.4.0
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004133
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004135
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064698
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2087186
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2129809
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135244
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135247
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135770
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135771
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2154086
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2169845
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2185707
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188542
- externalhttps://issues.redhat.com/browse/ENTMQST-4107
- externalhttps://issues.redhat.com/browse/ENTMQST-4541
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3223.json