First published: Tue Sep 01 2020(Updated: )
Red Hat Fuse provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat A-MQ is a standards compliant messaging system that is tailored for use in mission critical applications.<br>This patch is an update to Red Hat Fuse 6.3 and Red Hat A-MQ 6.3. It includes bug fixes, which are documented in the patch notes accompanying the package on the download page. See the download link given in the references section below.<br>Security fix(es):<br><li> commons-beanutils: apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)</li> <li> Camel: server-side template injection and arbitrary file disclosure on templating components (CVE-2020-11994)</li> <li> hawtio: server side request forgery via initial /proxy/ substring of a URI (CVE-2019-9827)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Fuse | ||
Red Hat AMQ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:3587 is classified as important.
To fix RHSA-2020:3587, update to the latest version of Red Hat Fuse 6.3 or other affected software as specified in the advisory.
RHSA-2020:3587 affects Red Hat Fuse and Red Hat A-MQ products.
There are no documented workarounds for RHSA-2020:3587, applying the patch is recommended.
RHSA-2020:3587 was released on October 28, 2020.