CVE-2020-14379

Related Vulnerabilities: CVE-2020-14379  

A flaw was found in broker. An XEE attack can used in Broker's configuration files, leading to DoS and information disclosure. The highest threat from the vulnerability is to system availability.

Description

A flaw was found in broker. An XEE attack can used in Broker's configuration files, leading to DoS and information disclosure. The highest threat from the vulnerability is to system availability.

Additional Information

  • Bugzilla 1840862: CVE-2020-14379 Red Hat AMQ broker: XXE injection in configuration files
  • CWE-611: Improper Restriction of XML External Entity Reference
  • FAQ: Frequently asked questions about CVE-2020-14379