RHSA-2023:5491MediumCVSS 6.5

Red Hat Security Advisory: Red Hat AMQ Broker 7.11.2 release and security update

Published
October 5, 2023
Last Modified
August 19, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-1664 — keycloak: Untrusted Certificate Validation CVE-2023-2976 — guava: insecure temporary directory creation CVE-2023-33008 — apache-johnzon: Prevent inefficient internal conversion from BigDecimal at large scale

🎯 Affected products1

  • AMQ Broker 7.11.2

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Make sure KC_SPI_TRUSTSTORE_FILE_FILE is correctly set and the logs are not reporting the "Cannot validate client certificate trust: Truststore not available" after an attempt to explore the vulnerability. Note this message may happen under other scenarios and reasons but the expected behavior would be that a non-valid certificate to pass. Workaround: Temp files should be created with sufficiently non-predictable names and in a secure-permissioned, dedicated temp folder.

🔗 References (8)