RHSA-2021:0986: Low: AMQ Online 1.7.0 release and security update
The release of Red Hat AMQ Online 1.7.0 serves as a replacement for earlier AMQ Online releases, and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References.Security Fix(es): fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise (CVE-2021-20218) netty: Information disclosure via the local system temporary directory (CVE-2021-21290) netty: possible request smuggling in HTTP/2 due missing validation (CVE-2021-21295) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0986?
RHSA-2021:0986 has a critical severity rating due to vulnerabilities in the fabric8-kubernetes-client.
How do I fix RHSA-2021:0986?
To fix RHSA-2021:0986, upgrade to the latest version of Red Hat AMQ Online as documented in the release notes.
Which products are affected by RHSA-2021:0986?
RHSA-2021:0986 affects users of Red Hat AMQ Online prior to version 1.7.0.
What vulnerabilities are addressed in RHSA-2021:0986?
RHSA-2021:0986 addresses vulnerabilities related to the fabric8-kubernetes-client that may allow unauthorized access.
Is there a workaround for RHSA-2021:0986?
There are no known workarounds for RHSA-2021:0986; upgrading is recommended to mitigate risks.