Lucene search

K
redhatRedHatRHSA-2020:5365
HistoryDec 08, 2020 - 8:51 a.m.

(RHSA-2020:5365) Moderate: Red Hat AMQ Broker 7.8 release and security update

2020-12-0808:51:34
access.redhat.com
65
red hat
amq broker
security update
activemq artemis
asynchronous journal
cve-2019-9827
cve-2020-13932
cve-2020-27216
cve-2015-5183
release notes

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.033

Percentile

91.5%

AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.

This release of Red Hat AMQ Broker 7.8.0 serves as a replacement for Red Hat AMQ Broker 7.7.0, and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.

Security Fix(es):

  • hawtio: server side request forgery via initial /proxy/ substring of a URI (CVE-2019-9827)

  • mqtt-client: activemq: remote XSS in web console diagram plugin (CVE-2020-13932)

  • jetty: local temporary directory hijacking vulnerability (CVE-2020-27216)

  • Hawtio: HTTPOnly and Secure attributes not set on cookies (CVE-2015-5183)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.033

Percentile

91.5%