RHSA-2014:1171: Important: Fuse ESB Enterprise/Fuse MQ Enterprise 7.1.0 update
Fuse ESB Enterprise is an integration platform based on Apache ServiceMix.Fuse MQ Enterprise, based on Apache ActiveMQ, is a standards-compliantmessaging system that is tailored for use in mission critical applications.Fuse ESB Enterprise and Fuse MQ Enterprise include the insight plug-in,which provides insight into a Fuse Fabric using Elasticsearch to query datafor logs, metrics or historic Camel messages. This plug-in is not enabledby default, and is provided as a technology preview. If it is enabled byinstalling the feature, for example:JBossFuse:karaf@root> features:install insight-elasticsearchThen an Elasticsearch server will be started. It was discovered that thedefault configuration of Elasticsearch enabled dynamic scripting, allowinga remote attacker to execute arbitrary MVEL expressions and Java code viathe source parameter passed to search. (CVE-2014-3120)All users of Fuse ESB Enterprise and Fuse MQ Enterprise 7.1.0 as providedfrom the Red Hat Customer Portal who have enabled Elasticsearch are advisedto follow the instructions provided in the Solution section of thisadvisory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:1171?
The severity of RHSA-2014:1171 is classified as important.
How do I fix RHSA-2014:1171?
To fix RHSA-2014:1171, you should apply the relevant updates provided in the advisory.
What software is affected by RHSA-2014:1171?
RHSA-2014:1171 affects Fuse ESB Enterprise and Fuse MQ Enterprise.
What vulnerabilities are addressed in RHSA-2014:1171?
RHSA-2014:1171 addresses multiple security vulnerabilities in the affected software.
Is there a workaround for RHSA-2014:1171?
There are no specific workarounds for RHSA-2014:1171; applying updates is recommended.