A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2023:1241 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2023:3223 | third party advisory vendor advisory |
https://access.redhat.com/security/cve/CVE-2023-0833 | third party advisory vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2169845 | third party advisory issue tracking |
https://github.com/square/okhttp/issues/6738 | third party advisory issue tracking exploit |