RHSA-2023:6878: Critical: Red Hat AMQ Broker 7.10.5 release and security update
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.<br>This release of Red Hat AMQ Broker 7.10.5 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.<br>Security Fix(es):<br><li> activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack (CVE-2023-46604)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:6878?
The severity of RHSA-2023:6878 is classified as important.
How do I fix RHSA-2023:6878?
To fix RHSA-2023:6878, update to Red Hat AMQ Broker 7.10.5 or later.
What specific vulnerabilities are addressed in RHSA-2023:6878?
RHSA-2023:6878 addresses security vulnerabilities that could lead to potential breaches or information leaks.
Is RHSA-2023:6878 related to a specific version of AMQ Broker?
Yes, RHSA-2023:6878 specifically addresses vulnerabilities in Red Hat AMQ Broker 7.x.
When was the advisory for RHSA-2023:6878 released?
The advisory for RHSA-2023:6878 was released in November 2023.