PT-2020-13977 · Red Hat · Amq Online
Published
2020-09-16
·
Updated
2020-09-23
·
CVE-2020-14348
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
AMQ Online versions prior to 1.5.2
Description
The issue arises when an invalid field is injected into a user's AddressSpace configuration within the user namespace, causing AMQ Online to enter an inconsistent state. This inconsistency leads to malfunctions in AMQ Online components, including failures in provisioning and address creation. However, existing messaging clients or brokers remain unaffected.
Recommendations
For versions prior to 1.5.2, update to version 1.5.2 or later to resolve the issue. As a temporary workaround, consider restricting modifications to the AddressSpace configuration to prevent injecting invalid fields until a patch is applied.
Fix
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amq Online