RHSA-2021:0384: Important: Red Hat JBoss Fuse/A-MQ 6.3 R18 security and bug fix update
Red Hat Fuse provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat A-MQ is a standards compliant messaging system that is tailored for use in mission critical applications.This patch is an update to Red Hat Fuse 6.3 and Red Hat A-MQ 6.3. It includes bug fixes, which are documented in the patch notes accompanying the package on the download page. See the download link given in the references section below.Security fix(es): shiro-core: shiro: specially crafted HTTP request may cause an authentication bypass [amq-6.3.0] (CVE-2020-13933) xstream: remote code execution due to insecure XML deserialization when relying on blocklists [amq-6.3.0] (CVE-2020-26217) xstream: remote code execution due to insecure XML deserialization when relying on blocklists [fuse-6.3.0] (CVE-2020-26217) broker: activemq: LDAP authentication bypass with anonymous bind [amq-6.3.0] (CVE-2021-26117) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0384?
The severity of RHSA-2021:0384 is classified as moderate.
How do I fix RHSA-2021:0384?
To fix RHSA-2021:0384, you should apply the updates provided by Red Hat for JBoss Fuse and A-MQ.
What products are affected by RHSA-2021:0384?
RHSA-2021:0384 affects Red Hat JBoss Fuse and Red Hat A-MQ.
When was RHSA-2021:0384 released?
RHSA-2021:0384 was released on April 7, 2021.
What are the risks of not addressing RHSA-2021:0384?
Not addressing RHSA-2021:0384 could expose systems to vulnerabilities that may lead to security breaches.