MEDIUM
Red hat a-mq streams: component version with information disclosure flaw
Published Sep 27, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.44%
Description
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.
Affected products
No data.
Configuration 2
OR
- < 2.2.1
- ≥ 2.3.0 · < 2.4.0
No data.
Red Hat AMQ Streams 2.2.1
n/a
Fixed · RHSA-2023:1241
Red Hat AMQ Streams 2.4.0
n/a
Fixed · RHSA-2023:3223
streams for Apache Kafka
okhttp
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Streams 2.2.1 | n/a | Fixed | RHSA-2023:1241 |
| Red Hat AMQ Streams 2.4.0 | n/a | Fixed | RHSA-2023:3223 |
| streams for Apache Kafka | okhttp | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://access.redhat.com/errata/RHSA-2023:1241 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:3223 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-0833 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2169845 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12835 Advisory
- https://github.com/square/okhttp/issues/6738 ExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-0833
- https://www.cve.org/CVERecord?id=CVE-2023-0833
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2023:1241 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2023:3223 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2023-0833 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2169845 | issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12835 | Advisory | |
| https://github.com/square/okhttp/issues/6738 | ExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-0833 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-0833 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 27, 2023
Updated Jun 23, 2026
Reserved Feb 14, 2023
Link CVE-2023-0833
CISA Vulnrichment
Updated May 10, 2024
GitHub
No data