First published: Wed Jul 29 2020(Updated: )
Injecting an invalid field to a user’s AddressSpace configuration of the user namespace puts AMQ in an inconsistent state, where the AMQ components of all of the other users do not operate properly, such as the failure of provisioning and the failure of creating addresses.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/amq-online-1.5.2 enmasse | <0.32.1 | 0.32.1 |
Redhat Amq Online | <1.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14348.
The severity of CVE-2020-14348 is medium with a CVSS score of 4.3.
CVE-2020-14348 affects AMQ Online version 1.5.2 and earlier.
Injecting an invalid field to a user's AddressSpace configuration can put AMQ Online in an inconsistent state, causing provisioning and address creation failures.
To fix CVE-2020-14348, upgrade to AMQ Online version 1.5.2 or later.