CVE-2020-14348

MEDIUM

AMQ Online < 1.5.2 - Denial of Service via Invalid AddressSpace Configuration Field

Title source: llm
STIX 2.1

Description

It was found in AMQ Online before 1.5.2 that injecting an invalid field to a user's AddressSpace configuration of the user namespace puts AMQ Online in an inconsistent state, where the AMQ Online components do not operate properly, such as the failure of provisioning and the failure of creating addresses, though this does not impact upon already existing messaging clients or brokers.

References (1)

Core 1
Core References
Issue Tracking x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1861814

Scores

CVSS v3 4.3
EPSS 0.0081
EPSS Percentile 51.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-754 CWE-248
Status published
Products (1)
redhat/amq_online < 1.5.2
Published Sep 16, 2020
Tracked Since Feb 18, 2026