RedHat: RHSA-2020-2751:01 Important: Red Hat AMQ Broker 7.7 release and

    Date 25 Jun 2020
    166
    Posted By LinuxSecurity Advisories
    Red Hat AMQ Broker 7.7 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256
    
    =====================================================================
                       Red Hat Security Advisory
    
    Synopsis:          Important: Red Hat AMQ Broker 7.7 release and security update
    Advisory ID:       RHSA-2020:2751-01
    Product:           Red Hat JBoss AMQ
    Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2751
    Issue date:        2020-06-25
    Keywords:          amq,messaging,integration,broker
    Cross references:  RHEA-2020:55005-01
    CVE Names:         CVE-2015-5183 CVE-2020-1953 CVE-2020-10727 
                       CVE-2020-11612 
    =====================================================================
    
    1. Summary:
    
    Red Hat AMQ Broker 7.7 is now available from the Red Hat Customer Portal.
    
    Red Hat Product Security has rated this update as having a security impact
    of Important. A Common Vulnerability Scoring System (CVSS) base score,
    which gives a detailed severity rating, is available for each vulnerability
    from the CVE link(s) in the References section.
    
    2. Description:
    
    AMQ Broker is a high-performance messaging implementation based on ActiveMQ
    Artemis. It uses an asynchronous journal for fast message persistence, and
    supports multiple languages, protocols, and platforms. 
    
    This release of Red Hat AMQ Broker 7.7.0 serves as a replacement for Red
    Hat AMQ Broker 7.6.0, and includes security and bug fixes, and
    enhancements. For further information, refer to the release notes linked to
    in the References section.
    
    Security Fix(es):
    
    * apache-commons-configuration: uncontrolled class instantiation when
    loading YAML files (CVE-2020-1953)
    
    * broker: resetUsers operation stores password in plain text (EMBARGOED
    CVE-2020-10727)
    
    * netty: compression/decompression codecs don't enforce limits on buffer
    allocation sizes (CVE-2020-11612)
    
    * A-MQ Console: HTTPOnly and Secure attributes not set on cookies
    (CVE-2015-5183)
    
    For more details about the security issue(s), including the impact, a CVSS
    score, and other related information, refer to the CVE page(s) listed in
    the References section.
    
    3. Solution:
    
    Before applying the update, back up your existing installation, including
    all applications, configuration files, databases and database settings, and
    so on.
    
    The References section of this erratum contains a download link (you must
    log in to download the update).
    
    4. Bugs fixed (https://bugzilla.redhat.com/):
    
    1249182 - CVE-2015-5183 Hawtio: HTTPOnly and Secure attributes not set on cookies
    1815212 - CVE-2020-1953 apache-commons-configuration: uncontrolled class instantiation when loading YAML files
    1816216 - CVE-2020-11612 netty: compression/decompression codecs don't enforce limits on buffer allocation sizes
    1827200 - CVE-2020-10727 broker: resetUsers operation stores password in plain text
    
    5. References:
    
    https://access.redhat.com/security/cve/CVE-2015-5183
    https://access.redhat.com/security/cve/CVE-2020-1953
    https://access.redhat.com/security/cve/CVE-2020-10727
    https://access.redhat.com/security/cve/CVE-2020-11612
    https://access.redhat.com/security/updates/classification/#important
    https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.7.0&productChanged=yes
    https://access.redhat.com/documentation/en-us/red_hat_amq/7.7/
    
    6. Contact:
    
    The Red Hat security contact is . More contact
    details at https://access.redhat.com/security/team/contact/
    
    Copyright 2020 Red Hat, Inc.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1
    
    iQIVAwUBXvSxstzjgjWX9erEAQgiUA//SN1p1lunK53FUcPw7SpwrLxIEg+JSEdS
    hgRJ+aFvFkVrR/cMTIbxyEuW5NG68bkaAf0qQbQEj9i2DYjcBMLvnIvcyNq2FK23
    x5KfA9ErmgQ3yXz8Jc7xqAmpAMKsMVpEhCkHEfAzD/0QQIdoI++P/NALpIo6ODy3
    UxnfszUaW3Yp0HImdhGVx6Ta8jJ8Ko2fIRR2YyP2c/FBlat+7FVSKUWT2+wegj3S
    ETI5n413TTvO/WuOI6Cb8B+c7AriWBelrys3wilstGlSK8d8F6Qcvi5Q+AMXWc9x
    24WrP/h4UQbYerDZvmzo32akd5Qb4nuQtvqXLeKakaMUIROlFjS2YUulf6sITKpI
    39754RjO/wN9EMd37S7mwromWW+fLOJQvrAIwFRCh+ccGpwSMGaB6+y8cYOl9+RP
    qbPg0kXmmp4fHhv7hIi9U4wm6oXt4SOglHyiif1nUAuIRehJh12pNzI+VgqD/1Hn
    O+1FbZGGw/xThUQqxUb3yRZtclqldf5FYo8q1b3MS+7E6m+ota0FvOFTXhzN23AE
    acK0BlKG9dnEYvmvi2SVAFhJP6Ycu91cpNR/VvAESuMHpt0IlrLJZPJOfe3JRTt/
    1AHmnjVPyaETW97SuKi7rDzHM5BbKjVQDg/BgZ3VOr4RN7s25Bt2IcFCFa/4ykt9
    zE6zWJ1dhH8=
    =NNkf
    -----END PGP SIGNATURE-----
    
    --
    RHSA-announce mailing list
    This email address is being protected from spambots. You need JavaScript enabled to view it.
    https://www.redhat.com/mailman/listinfo/rhsa-announce
    

    LinuxSecurity Poll

    Are you considering making the switch to Purism's new Librem 14 Linux laptop to improve your security and privacy online?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/31-are-you-considering-making-the-switch-to-purism-s-new-librem-14-linux-laptop-to-improve-your-security-and-privacy-online?task=poll.vote&format=json
    31
    radio
    [{"id":"109","title":"Yes - the hardware kill switches and default ad blocking\/tracking protection sold me on it.","votes":"3","type":"x","order":"1","pct":37.5,"resources":[]},{"id":"110","title":"Not sure yet - I need to do more research.","votes":"4","type":"x","order":"2","pct":50,"resources":[]},{"id":"111","title":"No - I'm satisfied with my current laptop and have no security\/privacy concerns.","votes":"1","type":"x","order":"3","pct":12.5,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
    bottom 200

    Advisories

    Please enable / Bitte aktiviere JavaScript!
    Veuillez activer / Por favor activa el Javascript![ ? ]

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.