-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat AMQ Streams 1.6.7 release and security update Advisory ID: RHSA-2022:0467-01 Product: Red Hat JBoss AMQ Advisory URL: https://access.redhat.com/errata/RHSA-2022:0467 Issue date: 2022-02-08 CVE Names: CVE-2021-4178 CVE-2021-44832 CVE-2022-23302 CVE-2022-23305 CVE-2022-23307 ===================================================================== 1. Summary: Red Hat AMQ Streams 1.6.7 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat AMQ Streams, based on the Apache Kafka project, offers a distributed backbone that allows microservices and other applications to share data with extremely high throughput and extremely low latency. This release of Red Hat AMQ Streams 1.6.7 serves as a replacement for Red Hat AMQ Streams 1.6.6, and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender (CVE-2022-23305) * log4j: Unsafe deserialization flaw in Chainsaw log viewer (CVE-2022-23307) * kubernetes-client: Insecure deserialization in unmarshalYaml method (CVE-2021-4178) * log4j-core: remote code execution via JDBC Appender (CVE-2021-44832) * log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink (CVE-2022-23302) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed (https://bugzilla.redhat.com/): 2034388 - CVE-2021-4178 kubernetes-client: Insecure deserialization in unmarshalYaml method 2035951 - CVE-2021-44832 log4j-core: remote code execution via JDBC Appender 2041949 - CVE-2022-23302 log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink 2041959 - CVE-2022-23305 log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender 2041967 - CVE-2022-23307 log4j: Unsafe deserialization flaw in Chainsaw log viewer 5. References: https://access.redhat.com/security/cve/CVE-2021-4178 https://access.redhat.com/security/cve/CVE-2021-44832 https://access.redhat.com/security/cve/CVE-2022-23302 https://access.redhat.com/security/cve/CVE-2022-23305 https://access.redhat.com/security/cve/CVE-2022-23307 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.streams&version=1.6.7 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYgKqGtzjgjWX9erEAQjqJg//d1l6vhkQTwqd2JAy7nqgZd8EWf9qyQPG n17MQcnCwEYg0uMX8qYbQO6QPb3XJuNfYBXHVPjzLhh6gXa5lm/0abnGIvG9Rgst poBYdoT/9RD5Gnq2s5GutFExPDjv6uiXFNpPiHTVu/UENpbcnCYpAaQJHccvmnRK GWFxHPAX+OEPcAo0BQ4zY3b4OZlI0OzJabnrRRrXAX3nK54Gydky9fkJT5kTxfu7 O4HxQ2vS8/PT+H3S7NUs1OszBaQmXQXkXHloe5rpvch0DbQQzKnbCUupO/jortGP YOSM0KYnX6BB+1bvmBD7/XNlBp48uimHUyWFu6ZW9y9cZF4ia2V909vEB3m9cTkv 0eoSdVtf5HbwWKmNfd7jdgYjRwDE6YkZAu7zSJ7HtMvt4hMftP8bivBzAUXk+v8S g5j6lbhqqDq2BHYL4udqQlUzdLQM3ayH9nilFdYQ0TSJIidpFjkurKtClONw/KWS hdu3mz24PBFkcr/iMZTIPHp3qzw0D37tUJBpomiY+TvNkIY73IllxtmL2JP+CL6p lK9b85jo+Zxrp6nifp9qSQinnj1XKrrkw3yRY4kH2USsVjSq0pEmilAY/pRXXQ6d zaaab/29L6e5vrkqx3grMYvs67UWee2i2ktiXmybgjcn8pjddqGh+Ry2zaLFvQdY 6487pT0AGLk= =pDsO -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce