CVE-2023-0833: Red hat a-mq streams: component version with information disclosure flaw
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.
Other sources
It was found that Red Hat's AMQ-Streams ships a version of OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. An authenticated attacker could possibly use this flaw to access information outside of their regular permissions.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0833?
CVE-2023-0833 is a vulnerability found in Red Hat's AMQ-Streams that allows an authenticated attacker to access information outside of their regular permissions.
What is the severity of CVE-2023-0833?
CVE-2023-0833 has a severity rating of medium (5.5).
Which software versions are affected by CVE-2023-0833?
Versions up to and excluding 4.9.2 of okhttp and versions up to and including 2.2.1 of Red Hat's A-mq Streams are affected by CVE-2023-0833.
How can an attacker exploit CVE-2023-0833?
An attacker can exploit CVE-2023-0833 by triggering an exception with a header containing an illegal value in their authenticated session.
Are there any remediation steps for CVE-2023-0833?
Yes, the recommended remediation is to update okhttp to version 4.9.2 or above and Red Hat's A-mq Streams to version 2.4.0 or above.