CVE-2021-4040: Medium severity redhat Amq Broker vulnerability
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this vulnerability is system availability.
Other sources
A flaw was found in the Red Hat AMQ Broker 7.9.0 and prior that allows an attacker to partially disrupt availability (DoS) through uncontrolled resource consumption of memory.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the AMQ Broker to trusted hosts and management networks using firewall rules, ACLs or network segmentation to reduce exposure to malicious, sustained message traffic.
- Compensating control
Deploy ingress filtering or rate-limiting at the edge (load balancer, proxy, or message gateway) to limit message send rate and/or size to the broker and mitigate uncontrolled resource consumption.
- Operational
Implement monitoring and alerting for broker memory usage and process health, and establish automated recovery/runbook steps (e.g., graceful restart, failover) so availability can be restored quickly if an OOM occurs.
- Operational
Apply vendor-supplied updates or patches for Red Hat AMQ Broker as soon as a fixed version or advisory is released by the vendor; verify and test updates before wide deployment.
Event History
Frequently Asked Questions
What is CVE-2021-4040?
CVE-2021-4040 is a vulnerability found in AMQ Broker that can cause a partial interruption to the availability of the broker due to an Out of Memory (OOM) condition.
How does CVE-2021-4040 affect AMQ Broker?
CVE-2021-4040 allows an attacker to partially disrupt the availability of AMQ Broker through a sustained attack of maliciously crafted messages.
What is the severity of CVE-2021-4040?
The severity of CVE-2021-4040 is medium with a CVSS score of 5.3.
Which versions of AMQ Broker and Apache ActiveMQ Artemis are affected by CVE-2021-4040?
AMQ Broker version up to 7.10.0 and Apache ActiveMQ Artemis version up to 2.19.1 are affected by CVE-2021-4040.
How can I fix CVE-2021-4040?
To fix CVE-2021-4040, update your AMQ Broker to a version beyond 7.10.0 and Apache ActiveMQ Artemis to a version beyond 2.19.1.