RHSA-2020:3587: Important: Red Hat JBoss Fuse/A-MQ 6.3 R17 security and bug fix update
Red Hat Fuse provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat A-MQ is a standards compliant messaging system that is tailored for use in mission critical applications.This patch is an update to Red Hat Fuse 6.3 and Red Hat A-MQ 6.3. It includes bug fixes, which are documented in the patch notes accompanying the package on the download page. See the download link given in the references section below.Security fix(es): commons-beanutils: apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086) Camel: server-side template injection and arbitrary file disclosure on templating components (CVE-2020-11994) hawtio: server side request forgery via initial /proxy/ substring of a URI (CVE-2019-9827) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3587?
The severity of RHSA-2020:3587 is classified as important.
How do I fix RHSA-2020:3587?
To fix RHSA-2020:3587, update to the latest version of Red Hat Fuse 6.3 or other affected software as specified in the advisory.
What are the impacted products in RHSA-2020:3587?
RHSA-2020:3587 affects Red Hat Fuse and Red Hat A-MQ products.
Is there a workaround for RHSA-2020:3587?
There are no documented workarounds for RHSA-2020:3587, applying the patch is recommended.
When was RHSA-2020:3587 released?
RHSA-2020:3587 was released on October 28, 2020.