First published: Tue Feb 14 2023(Updated: )
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Squareup Okhttp | <4.9.2 | |
Redhat A-mq Streams | <2.2.1 | |
Redhat A-mq Streams | >=2.3.0<2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0833 is a vulnerability found in Red Hat's AMQ-Streams that allows an authenticated attacker to access information outside of their regular permissions.
CVE-2023-0833 has a severity rating of medium (5.5).
Versions up to and excluding 4.9.2 of okhttp and versions up to and including 2.2.1 of Red Hat's A-mq Streams are affected by CVE-2023-0833.
An attacker can exploit CVE-2023-0833 by triggering an exception with a header containing an illegal value in their authenticated session.
Yes, the recommended remediation is to update okhttp to version 4.9.2 or above and Red Hat's A-mq Streams to version 2.4.0 or above.