First published: Thu Oct 05 2023(Updated: )
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.<br>This release of Red Hat AMQ Broker 7.11.2 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.<br>Security Fix(es):<br><li> guava: insecure temporary directory creation (CVE-2023-2976)</li> <li> apache-johnzon: Prevent inefficient internal conversion from BigDecimal at large scale (CVE-2023-33008)</li> <li> keycloak: Untrusted Certificate Validation (CVE-2023-1664)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Red Hat JBoss Middleware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:5491 is moderate.
The title of RHSA-2023:5491 is 'Moderate: Red Hat AMQ Broker 7.11.2 release and security update'.
The affected software for RHSA-2023:5491 is Red Hat JBoss Middleware.
To fix RHSA-2023:5491, apply the Red Hat AMQ Broker 7.11.2 release and security update.
You can find more information about RHSA-2023:5491 on the Red Hat Customer Portal and Bugzilla.