First published: Thu Mar 25 2021(Updated: )
The release of Red Hat AMQ Online 1.7.0 serves as a replacement for earlier AMQ Online releases, and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References.<br>Security Fix(es):<br><li> fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise (CVE-2021-20218)</li> <li> netty: Information disclosure via the local system temporary directory (CVE-2021-21290)</li> <li> netty: possible request smuggling in HTTP/2 due missing validation (CVE-2021-21295)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat AMQ Online |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2021:0986 has a critical severity rating due to vulnerabilities in the fabric8-kubernetes-client.
To fix RHSA-2021:0986, upgrade to the latest version of Red Hat AMQ Online as documented in the release notes.
RHSA-2021:0986 affects users of Red Hat AMQ Online prior to version 1.7.0.
RHSA-2021:0986 addresses vulnerabilities related to the fabric8-kubernetes-client that may allow unauthorized access.
There are no known workarounds for RHSA-2021:0986; upgrading is recommended to mitigate risks.