RHSA-2024:6893: Moderate: Red Hat AMQ Broker 7.12.0 release and security update
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.<br>This release of Red Hat AMQ Broker 7.12.0 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.<br>Security Fix(es):<br><li> (CVE-2023-34455) snappy-java: Unchecked chunk length leads to DoS</li> <li> (CVE-2023-35116) jackson-databind: denial of service via cylic dependencies</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Moderate: Red Hat AMQ Broker 7.12.0 release and security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:6893?
The severity of RHSA-2024:6893 is classified as important.
How do I fix RHSA-2024:6893?
To fix RHSA-2024:6893, apply the latest security updates provided by Red Hat for AMQ Broker 7.12.0.
What products are affected by RHSA-2024:6893?
RHSA-2024:6893 affects Red Hat JBoss Middleware products utilizing AMQ Broker.
What are the security risks associated with RHSA-2024:6893?
RHSA-2024:6893 addresses vulnerabilities that may allow unauthorized access or disruption of messaging services.
Is additional configuration required after fixing RHSA-2024:6893?
In most cases, no additional configuration is required after applying the fix for RHSA-2024:6893.