Moderate: AMQ Broker 7.13.0.OPR.1.GA Container Images security update
Moderate: Red Hat AMQ Broker 7.13.0 release and security update
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.<br>This release of Red Hat AMQ Broker 7.12.0 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.<br>Security Fix(es):<br><li> (CVE-2023-34455) snappy-java: Unchecked chunk length leads to DoS</li> <li> (CVE-2023-35116) jackson-databind: denial of service via cylic dependencies</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.This release of Red Hat AMQ Broker 7.10.7 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.Security Fix(es): (CVE-2023-5072) JSON-java: parser confusion leads to OOM (CVE-2024-1132) keycloak: path transversal in redirection validation For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.This release of Red Hat AMQ Broker 7.11.7 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.Security Fix(es): (CVE-2023-5072) JSON-java: parser confusion leads to OOM (CVE-2024-1132) keycloak: path transversal in redirection validation For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Important: Red Hat AMQ Broker 7.12.0 release and security update
Important: Red Hat Process Automation Manager 7.13.5 security update
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.<br>This release of Red Hat AMQ Broker 7.10.6 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.<br>Security Fix(es):<br><li> (CVE-2023-44981) zookeeper: Authorization Bypass in Apache ZooKeeper</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: Red Hat AMQ Broker 7.11.6 release and security update
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.This release of Red Hat AMQ Broker 7.11.5 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.Security Fix(es): (CVE-2023-33201) bouncycastle: potential blind LDAP injection attack using a self-signed certificate For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Important: Red Hat AMQ Streams 2.6.0 release and security update
Important: Red Hat Process Automation Manager 7.13.4 security one-off update
Important: Red Hat Build of OptaPlanner 8.38.0 SP2 security update
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.This release of Red Hat AMQ Broker 7.10.4 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.Security Fix(es): (CVE-2023-44487) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.This release of Red Hat AMQ Broker 7.11.3 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.Security Fix(es): (CVE-2023-44487) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) NOTE: A Red Hat Security Bulletin which addresses further details about this flaw is available in the References section. (CVE-2023-34462) netty: io.netty:netty-handler: SniHandler 16MB allocation (CVE-2023-40167) jetty: Improper validation of HTTP/1 content-length (CVE-2023-41080) tomcat: Open Redirect vulnerability in FORM authentication For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms.This release of Red Hat AMQ Broker 7.11.2 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.Security Fix(es): guava: insecure temporary directory creation (CVE-2023-2976) apache-johnzon: Prevent inefficient internal conversion from BigDecimal at large scale (CVE-2023-33008) keycloak: Untrusted Certificate Validation (CVE-2023-1664) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Important: Red Hat Build of OptaPlanner 8.38.0 SP1
Moderate: AMQ Broker 7.11.1.OPR.2.GA Container Images Release
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
A new release for Red Hat Build of OptaPlanner 8.38.0 for Quarkus 2.13.8 including security updates is now available. The purpose of this text-only errata is to inform you about the security issues fixed.Red Hat Product Security has rated this update as having an impact ofImportant.A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.Security Fix(es): CVE-2023-20883 spring-boot: Spring Boot Welcome Page DoS Vulnerability
Important: Red Hat AMQ Streams 2.4.0 release and security update
Apache Kafka before versions 0.10.2.2, 0.11.0.3, 1.0.1 and 1.1.0 allow users to perform actions reserved for the Broker via manually created fetch requests that interfere with data replication, resulting in data loss.
External Reference:
https://lists.apache.org/thread.html/29f61337323f48c47d4b41d74b9e452bd60e65d0e5103af9a6bb2fef@%3Cusers.kafka.apache.org%3E
Upstream Patches:
https://github.com/apache/kafka/commit/d2932ad370c5b56edac9d99e6d75f199537a569f https://github.com/apache/kafka/commit/580f743c3ce633241d6076ce83fb778cea86a1f6 https://github.com/apache/kafka/commit/51f0f3ee792cf9352ce61afeca098c765cdad664
Last updated 22 August 2024
A flaw was found in JBoss web services where the services used a weak symmetric encryption protocol, PKCS#1 v1.5. An attacker could use this weakness in chosen-ciphertext attacks to recover the symmetric key and conduct further attacks.