Is CVE-2023-46604 really fixed in AMQ 7.11.4 ?
Issue
According to RHSA-2023:6879, CVE-46604 is fixed in AMQ 7.11.4. However, the file activemq-openwire-legacy-5.11.0.redhat-630517.jar
is dated January 2023, before the CVE was fixed.
So has the fixed really been applied?
Environment
- Red Hat AMQ
- 7.11.4
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.