RHSA-2020:4154: Moderate: Red Hat AMQ Broker 7.4.5 release and security update
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms. This release of Red Hat AMQ Broker 7.4.5 serves as a replacement for Red Hat AMQ Broker 7.4.4, and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.Security Fix(es): hawtio: server side request forgery via initial /proxy/ substring of a URI (CVE-2019-9827) hawtio: HTTPOnly and Secure attributes not set on cookies (CVE-2015-5183) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4154?
The severity of RHSA-2020:4154 is classified as moderate.
How do I fix RHSA-2020:4154?
To address RHSA-2020:4154, you should update to the latest version of Red Hat AMQ Broker 7.4.5.
What does RHSA-2020:4154 impact?
RHSA-2020:4154 impacts the Red Hat AMQ Broker, a messaging implementation based on ActiveMQ Artemis.
Is there a workaround for RHSA-2020:4154?
There is no recommended workaround for RHSA-2020:4154; the best course of action is to apply the update.
When was RHSA-2020:4154 released?
RHSA-2020:4154 was released on November 4, 2020.