Linux Security
    Linux Security
    Linux Security

    RedHat: RHSA-2020-3133:01 Important: Red Hat AMQ Broker 7.4.4 release and

    Date
    209
    Posted By
    Red Hat AMQ Broker 7.4.4 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256
    
    =====================================================================
                       Red Hat Security Advisory
    
    Synopsis:          Important: Red Hat AMQ Broker 7.4.4 release and security update
    Advisory ID:       RHSA-2020:3133-01
    Product:           Red Hat JBoss AMQ
    Advisory URL:      https://access.redhat.com/errata/RHSA-2020:3133
    Issue date:        2020-07-23
    Keywords:          amq,messaging,integration,broker
    Cross references:  RHBA-2020:56706-01
    CVE Names:         CVE-2018-15756 CVE-2020-1953 CVE-2020-10727 
                       CVE-2020-11612 
    =====================================================================
    
    1. Summary:
    
    Red Hat AMQ Broker 7.4.4 is now available from the Red Hat Customer Portal.
    
    Red Hat Product Security has rated this update as having a security impact
    of Important. A Common Vulnerability Scoring System (CVSS) base score,
    which gives a detailed severity rating, is available for each vulnerability
    from the CVE link(s) in the References section.
    
    2. Description:
    
    AMQ Broker is a high-performance messaging implementation based on ActiveMQ
    Artemis. It uses an asynchronous journal for fast message persistence, and
    supports multiple languages, protocols, and platforms. 
    
    This release of Red Hat AMQ Broker 7.4.4 serves as a replacement for Red
    Hat AMQ Broker 7.4.3, and includes security and bug fixes, and
    enhancements. For further information, refer to the release notes linked to
    in the References section.
    
    Security Fix(es):
    
    * apache-commons-configuration: uncontrolled class instantiation when
    loading YAML files (CVE-2020-1953)
    
    * broker: resetUsers operation stores password in plain text (EMBARGOED
    CVE-2020-10727)
    
    * netty: compression/decompression codecs don't enforce limits on buffer
    allocation sizes (CVE-2020-11612)
    
    * springframework: DoS Attack via Range Requests (CVE-2018-15756)
    
    For more details about the security issue(s), including the impact, a CVSS
    score, and other related information, refer to the CVE page(s) listed in
    the References section.
    
    3. Solution:
    
    Before applying the update, back up your existing installation, including
    all applications, configuration files, databases and database settings, and
    so on.
    
    The References section of this erratum contains a download link (you must
    log in to download the update).
    
    4. Bugs fixed (https://bugzilla.redhat.com/):
    
    1643043 - CVE-2018-15756 springframework: DoS Attack via Range Requests
    1815212 - CVE-2020-1953 apache-commons-configuration: uncontrolled class instantiation when loading YAML files
    1816216 - CVE-2020-11612 netty: compression/decompression codecs don't enforce limits on buffer allocation sizes
    1827200 - CVE-2020-10727 broker: resetUsers operation stores password in plain text
    
    5. References:
    
    https://access.redhat.com/security/cve/CVE-2018-15756
    https://access.redhat.com/security/cve/CVE-2020-1953
    https://access.redhat.com/security/cve/CVE-2020-10727
    https://access.redhat.com/security/cve/CVE-2020-11612
    https://access.redhat.com/security/updates/classification/#important
    https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.4.4&productChanged=yes
    https://access.redhat.com/documentation/en-us/red_hat_amq/7.4/
    
    6. Contact:
    
    The Red Hat security contact is . More contact
    details at https://access.redhat.com/security/team/contact/
    
    Copyright 2020 Red Hat, Inc.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1
    
    iQIVAwUBXxmol9zjgjWX9erEAQgmsw/+LIRB5EgPhKJYAf8PH2y2ZnSc7o70Gcrz
    utCOWTGjiDhRfYuQVNbjwIQ1JeVgBpXTE1wZygD4nqTBskx3FQzw4YmjLkH9R3Js
    Y85dzFC8go3fYjQ44vu1w28YwYBj1eFySZM4468SgD9bIZUxgiZjDyM+CNsYZEs5
    qyzFLVCZMRw10ifpzT209TGzxJLJR91Y0eY6E0UZfzrdJu/4GYh9LDVfvlbhM1ts
    9zhczkNAc+6b082GbAsupWCE1pKVa7F/cf72EkT/0Sl1uvIGtamTPo1DvIuUofxD
    NFadGPYJDLCShGZwiN95wVcCx1BPaLGangn8lwNAZMg3+nJLOKljwwAw1MLkf4sZ
    ULlnS6TMR+mThkS9LIWpNLZ1aa2mrzD6NFXbDjMkCugocr3qddSGKMfLLwiFfT4k
    vs6c6JB/8e3xMb1jeT3oPe7Ew2tUcFXtk9zTUVCsHJB9169/v8s2zMPXjPqyLfL3
    wuiZM08g4cDilRPiAB+reUr1ompvYZlCGaTph5+twKSi1MLouADApj6L9oEumJSe
    3aTnHSKOfwGMF+B0jAK45iCV0gavhWtHtQDDS3OXOr8oTrrt5VZ2uGOZFQV2HP23
    GkEO3O6vK7xJ8HBq1mdxKCwoNQLAqBYZBBWbtoTcW4frWEb7xS7Xh3bYa1vPPVz8
    9WoYO3DWjCU=
    =n7mn
    -----END PGP SIGNATURE-----
    
    --
    RHSA-announce mailing list
    This email address is being protected from spambots. You need JavaScript enabled to view it.
    https://www.redhat.com/mailman/listinfo/rhsa-announce
    

    LinuxSecurity Poll

    Which aspect of server security are you most interested in learning more about?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/38-which-aspect-of-server-security-are-you-most-interested-in-learning-more-about?task=poll.vote&format=json
    38
    radio
    [{"id":"131","title":"Preventing information leakage","votes":"1","type":"x","order":"1","pct":100,"resources":[]},{"id":"132","title":"Firewall considerations","votes":"0","type":"x","order":"2","pct":0,"resources":[]},{"id":"133","title":"Permissions ","votes":"0","type":"x","order":"3","pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350


    VIEW MORE POLLS

    bottom 200

    Please enable / Bitte aktiviere JavaScript!
    Veuillez activer / Por favor activa el Javascript![ ? ]

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.