First published: Wed Sep 10 2014(Updated: )
Red Hat JBoss Fuse, based on Apache ServiceMix, provides a small-footprint,<br>flexible, open source enterprise service bus and integration platform. Red<br>Hat JBoss A-MQ, based on Apache ActiveMQ, is a standards-compliant<br>messaging system that is tailored for use in mission critical applications.<br>Red Hat JBoss Fuse and A-MQ include the insight plug-in, which provides<br>insight into a Fuse Fabric using Elasticsearch to query data for logs,<br>metrics or historic Camel messages. This plug-in is not enabled by default,<br>and is provided as a technology preview. If it is enabled by installing the<br>feature, for example:<br>JBossFuse:karaf@root> features:install insight-elasticsearch<br>Then an Elasticsearch server will be started. It was discovered that the<br>default configuration of Elasticsearch enabled dynamic scripting, allowing<br>a remote attacker to execute arbitrary MVEL expressions and Java code via<br>the source parameter passed to _search. (CVE-2014-3120)<br>All users of Red Hat JBoss Fuse and A-MQ 6.1.0 as provided from the Red Hat<br>Customer Portal who have enabled Elasticsearch are advised to follow the<br>instructions provided in the Solution section of this advisory.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.