-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: Migration Toolkit for Runtimes security bug fix and enhancement update
Advisory ID:       RHSA-2023:1285-01
Product:           Migration Toolkit for Runtimes
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:1285
Issue date:        2023-03-16
CVE Names:         CVE-2022-3782 CVE-2022-31690 CVE-2022-46364 
====================================================================
1. Summary:

Migration Toolkit for Runtimes 1.0.2 release

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Migration Toolkit for Runtimes 1.0.2 ZIP artifacts

Security Fix(es):

* keycloak: path traversal via double URL encoding (CVE-2022-3782)

* spring-security-oauth2-client: Privilege Escalation in
spring-security-oauth2-client (CVE-2022-31690)

* Apache CXF: SSRF Vulnerability (CVE-2022-46364)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2138971 - CVE-2022-3782 keycloak: path traversal via double URL encoding
2155682 - CVE-2022-46364 Apache CXF: SSRF Vulnerability
2162200 - CVE-2022-31690 spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client

5. References:

https://access.redhat.com/security/cve/CVE-2022-3782
https://access.redhat.com/security/cve/CVE-2022-31690
https://access.redhat.com/security/cve/CVE-2022-46364
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=migration.toolkit.runtimes&downloadType=distributions

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBZBLeC9zjgjWX9erEAQhOgxAAk/jRsjkrCxiJurClPSOMhcoTrWW8klIH
2YdMia9aPsx2g8qkN7VVUflIu5EoQArGMYqicWAfp5FjkTu7zCCk+VTGjJlScxzD
07tv3ZllsNG8HAmQPiUfbwiAcqS6p0TGhCqbR6qusVnhSOW3S7n817IX2dVkPWOM
z8/J7UpG0ewJX+DTZ7sFCv6QfJTN5hbKZMks6OsWRl3H4Xo0PCt9S/KK2tXNQTsi
kJz06WMN+AcCMYzy7BrdFdbMNpWuY7VHBUeK074Awc+18+LMD4Ed/qiCMoYVxn2K
ui2O9ldlLzT6OQerKHdWhcAYHNk/yh7ufFgznte4e0ePDsVEK/7q4NLCzLjFd1S5
n4weYCtg7BUGj4oR0hNEq/2eejarh6PBxP0rGYW/uIPP3Kfge2gz8KNRPIvCDcy0
4C0DrFTxcN3mcYNTawso6EgUDqsJNtOLykwgOjhYb5Re59PU4T+7FFHZW+xPuJMQ
bzBk2u0Z0PUKyh8UTPCdoLC06I6tpUGkKKwMEVO0VVg7l0QP8m/oHj35gnIgKrVl
vMzJNkRBK48pU57E6Ps1rDOA7/JiNwieuD2QoJuQRGo+Z98L3VZzSIUvtyjy4+Rj
4y1H1ttN02I3lwbPCtEBE2qu6R24karIVJtyLV1x4QsfLnyINiFm4upf2eEInVU3
w4QAo3uuIhA=pwgJ
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-1285:01 Important: Migration Toolkit for Runtimes

Migration Toolkit for Runtimes 1.0.2 release Red Hat Product Security has rated this update as having a security impact of Important

Summary

Migration Toolkit for Runtimes 1.0.2 ZIP artifacts
Security Fix(es):
* keycloak: path traversal via double URL encoding (CVE-2022-3782)
* spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client (CVE-2022-31690)
* Apache CXF: SSRF Vulnerability (CVE-2022-46364)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2022-3782 https://access.redhat.com/security/cve/CVE-2022-31690 https://access.redhat.com/security/cve/CVE-2022-46364 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=migration.toolkit.runtimes&downloadType=distributions

Package List


Severity
Advisory ID: RHSA-2023:1285-01
Product: Migration Toolkit for Runtimes
Advisory URL: https://access.redhat.com/errata/RHSA-2023:1285
Issued Date: : 2023-03-16
CVE Names: CVE-2022-3782 CVE-2022-31690 CVE-2022-46364

Topic

Migration Toolkit for Runtimes 1.0.2 releaseRed Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2138971 - CVE-2022-3782 keycloak: path traversal via double URL encoding

2155682 - CVE-2022-46364 Apache CXF: SSRF Vulnerability

2162200 - CVE-2022-31690 spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client


Related News