First published: Wed Sep 10 2014(Updated: )
Fuse ESB Enterprise is an integration platform based on Apache ServiceMix.<br>Fuse MQ Enterprise, based on Apache ActiveMQ, is a standards-compliant<br>messaging system that is tailored for use in mission critical applications.<br>Fuse ESB Enterprise and Fuse MQ Enterprise include the insight plug-in,<br>which provides insight into a Fuse Fabric using Elasticsearch to query data<br>for logs, metrics or historic Camel messages. This plug-in is not enabled<br>by default, and is provided as a technology preview. If it is enabled by<br>installing the feature, for example:<br>JBossFuse:karaf@root> features:install insight-elasticsearch<br>Then an Elasticsearch server will be started. It was discovered that the<br>default configuration of Elasticsearch enabled dynamic scripting, allowing<br>a remote attacker to execute arbitrary MVEL expressions and Java code via<br>the source parameter passed to _search. (CVE-2014-3120)<br>All users of Fuse ESB Enterprise and Fuse MQ Enterprise 7.1.0 as provided<br>from the Red Hat Customer Portal who have enabled Elasticsearch are advised<br>to follow the instructions provided in the Solution section of this<br>advisory.<br>
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.