REDHAT-BUG-2457275: High severity Apache ActiveMQ Client vulnerability
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS.
Note: TLS versions before TLSv1.3 (such as TLSv1.2) are broken but are not vulnerable to OOM. Previous TLS versions require a full handshake renegotiation which causes a connection to hang but not OOM. This is fixed as well. This issue affects Apache ActiveMQ Client: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.4.
Users are recommended to upgrade to version 6.2.4 or 5.19.5, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ActiveMQ Clientto a version that resolves this vulnerability.Fixed in 5.19.5 - Upgrade
Upgrade
Apache ActiveMQ Brokerto a version that resolves this vulnerability.Fixed in 5.19.5 - Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 5.19.5 - Upgrade
Upgrade
Apache ActiveMQ Clientto a version that resolves this vulnerability.Fixed in 6.2.4 - Upgrade
Upgrade
Apache ActiveMQ Brokerto a version that resolves this vulnerability.Fixed in 6.2.4 - Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 6.2.4
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2457275?
The severity of REDHAT-BUG-2457275 is high with a score of 7.
What software is affected by REDHAT-BUG-2457275?
The affected software includes Apache ActiveMQ Client, Apache ActiveMQ Broker, and Apache ActiveMQ.
How do I fix REDHAT-BUG-2457275?
Fixing REDHAT-BUG-2457275 involves updating to the latest version of Apache ActiveMQ that addresses the Out of Memory vulnerability.
What type of vulnerability is REDHAT-BUG-2457275 associated with?
REDHAT-BUG-2457275 is associated with a Denial of Service vulnerability.
What causes the vulnerability in REDHAT-BUG-2457275?
The vulnerability in REDHAT-BUG-2457275 is caused by improper handling of TLSv1.3 handshake KeyUpdates in ActiveMQ NIO SSL transports.