5.9
CVSSv3

CVE-2020-14319

Published: 03/08/2020 Updated: 12/08/2020
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 5.9 | Impact Score: 4.2 | Exploitability Score: 1.6
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P

Vulnerability Summary

It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks are not instigated or bypassed. For example authorised users using an older browser with Adobe Flash are vulnerable when targeted by an attacker. This flaw affects all versions of AMQ-Online before 1.5.2 and Enmasse versions 0.31.0-rc1 up until but not including 0.32.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat amq online

redhat enmasse

Vendor Advisories

Synopsis Moderate: AMQ Online 152 release and security update Type/Severity Security Advisory: Moderate Topic An update of the Red Hat OpenShift Container Platform 311 and 44/45 container images is now available for Red Hat AMQ OnlineRed Hat Product Security has rated this update as having a security ...