Vulnerability record · CVE-2021-3763 · published 23 August 2022
CVE-2021-3763: Redhat amq broker incorrect authorization vulnerability
Redhat · Amq Broker
A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are incorrectly checked, some privileged meta information such as queue names and configuration details are disclosed but the impact is limited as not all information is accessible and there is no affect to integrity.
Description
A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are incorrectly checked, some privileged meta information such as queue names and configuration details are disclosed but the impact is limited as not all information is accessible and there is no affect to integrity.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2021-3763 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2000654 | Issue TrackingVendor Advisory |
| https://issues.redhat.com/browse/ENTMQBR-5372 | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2021-3763 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2000654 | Issue TrackingVendor Advisory |
| https://issues.redhat.com/browse/ENTMQBR-5372 | Vendor Advisory |
Track CVE-2021-3763 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3763), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.