File disclosure and service interruption via external entities
Published Aug 16, 2022 · Updated Aug 4, 2024
XML external entity injection in Red Hat AMQ Broker 7 allows high-privileged local users to read files and exhaust resources. The broker configuration parser resolves attacker-controlled external entities unless artemis.disableXxe is enabled, permitting file URI reads or recursive entity expansion. Exploitation requires privileged local ability to alter a broker configuration file; processing can disclose broker-readable files or exhaust CPU and memory until service interruption.
Summary
What happened
XML external entity injection in Red Hat AMQ Broker 7 allows high-privileged local users to read files and exhaust resources. The broker configuration parser resolves attacker-controlled external entities unless artemis.disableXxe is enabled, permitting file URI reads or recursive entity expansion. Exploitation requires privileged local ability to alter a broker configuration file; processing can disclose broker-readable files or exhaust CPU and memory until service interruption.
The record
- CVE
- CVE-2020-14379
- Published
- Aug 16, 2022
- Updated
- Aug 4, 2024
- Vendor
- 389 Directory Server
- Product
- Red Hat AMQ Broker
- Classifications
- CWE-611, T1005
- Attack vector
- local
- Privileges
- admin
Timeline
How it unfolded
- Aug 16, 2022CVE publishedPublication date reported by the CVE source.
- Aug 4, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=Red Hat AMQ 7
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo