CVE-2020-14348: Medium severity red hat amq online vulnerability
Injecting an invalid field to a user’s AddressSpace configuration of the user namespace puts AMQ in an inconsistent state, where the AMQ components of all of the other users do not operate properly, such as the failure of provisioning and the failure of creating addresses.
Other sources
It was found in AMQ Online before 1.5.2 that injecting an invalid field to a user's AddressSpace configuration of the user namespace puts AMQ Online in an inconsistent state, where the AMQ Online components do not operate properly, such as the failure of provisioning and the failure of creating addresses, though this does not impact upon already existing messaging clients or brokers.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-14348.
What is the severity of CVE-2020-14348?
The severity of CVE-2020-14348 is medium with a CVSS score of 4.3.
How does CVE-2020-14348 affect AMQ Online?
CVE-2020-14348 affects AMQ Online version 1.5.2 and earlier.
What is the impact of CVE-2020-14348?
Injecting an invalid field to a user's AddressSpace configuration can put AMQ Online in an inconsistent state, causing provisioning and address creation failures.
How can CVE-2020-14348 be fixed?
To fix CVE-2020-14348, upgrade to AMQ Online version 1.5.2 or later.