CVE-2021-3763
A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console.
Does this matter?
Lower severity and a low EPSS score (0.68%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are incorrectly checked, some privileged meta information such as queue names and configuration details are disclosed but the impact is limited as not all information is accessible and there is no affect to integrity.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.68% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- redhat/amq broker
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2021-3763Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2000654Issue Tracking, Vendor Advisory
- https://issues.redhat.com/browse/ENTMQBR-5372Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2021-3763Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2000654Issue Tracking, Vendor Advisory
- https://issues.redhat.com/browse/ENTMQBR-5372Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.