RHSA-2024:3527MediumCVSS 9.8

Red Hat Security Advisory: Red Hat AMQ Streams 2.7.0 release and security update

Published
May 30, 2024
Last Modified
August 6, 2026

🔗 CVE IDs covered (17)

📋 Description

CVE-2021-3520 — lz4: memory corruption due to an integer overflow bug caused by memmove argument CVE-2021-24032 — zstd: Race condition allows attacker to access world-readable destination file CVE-2022-3171 — protobuf-java: timeout in parser leads to DoS CVE-2022-4899 — zstd: mysql: buffer overrun in util.c CVE-2022-42889 — apache-commons-text: variable interpolation RCE CVE-2022-42920 — Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing CVE-2023-1370 — json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) CVE-2023-2976 — guava: insecure temporary directory creation CVE-2023-33201 — bouncycastle: potential blind LDAP injection attack using a self-signed certificate CVE-2023-33202 — bc-java: Out of memory while parsing ASN.1 crafted data in org.bouncycastle.openssl.PEMParser class CVE-2023-43642 — snappy-java: Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impact CVE-2023-51074 — json-path: stack-based buffer overflow in Criteria.parse method CVE-2024-1023 — io.vertx/vertx-core: memory leak due to the use of Netty FastThreadLocal data structures in Vertx CVE-2024-1300 — io.vertx:vertx-core: memory leak when a TCP server is configured with TLS and SNI support CVE-2024-2700 — quarkus-core: Leak of local configuration properties into Quarkus applications CVE-2024-25710 — commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file CVE-2024-29025 — netty-codec-http: Allocation of Resources Without Limits or Throttling

🎯 Affected products1

  • Red Hat AMQ Streams 2.7.0

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: This flaw may be avoided by ensuring that any external inputs used with the Commons-Text lookup methods are sanitized properly. Untrusted input should always be thoroughly sanitized before using in any potentially risky situations. Workaround: Temp files should be created with sufficiently non-predictable names and in a secure-permissioned, dedicated temp folder. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Currently, no mitigation is available for this vulnerability. Please update as the patches become available. Workaround: No mitigation is currently available for this vulnerability.

🔗 References (27)