PT-2020-13977 · Red Hat · Amq Online

Published

2020-09-16

·

Updated

2020-09-23

·

CVE-2020-14348

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions AMQ Online versions prior to 1.5.2
Description The issue arises when an invalid field is injected into a user's AddressSpace configuration within the user namespace, causing AMQ Online to enter an inconsistent state. This inconsistency leads to malfunctions in AMQ Online components, including failures in provisioning and address creation. However, existing messaging clients or brokers remain unaffected.
Recommendations For versions prior to 1.5.2, update to version 1.5.2 or later to resolve the issue. As a temporary workaround, consider restricting modifications to the AddressSpace configuration to prevent injecting invalid fields until a patch is applied.

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14348

Affected Products

Amq Online