-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: Migration Toolkit for Runtimes security bug fix and enhancement update
Advisory ID:       RHSA-2023:1286-01
Product:           Migration Toolkit for Runtimes
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:1286
Issue date:        2023-03-16
CVE Names:         CVE-2021-46848 CVE-2022-2056 CVE-2022-2057 
                   CVE-2022-2058 CVE-2022-2519 CVE-2022-2520 
                   CVE-2022-2521 CVE-2022-2867 CVE-2022-2868 
                   CVE-2022-2869 CVE-2022-2953 CVE-2022-4415 
                   CVE-2022-31690 CVE-2022-35737 CVE-2022-40303 
                   CVE-2022-40304 CVE-2022-41966 CVE-2022-42010 
                   CVE-2022-42011 CVE-2022-42012 CVE-2022-43680 
                   CVE-2022-46364 CVE-2022-47629 CVE-2023-21835 
                   CVE-2023-21843 
====================================================================
1. Summary:

Migration Toolkit for Runtimes 1.0.2 release

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Migration Toolkit for Runtimes 1.0.2 Images

Security Fix(es):

* spring-security-oauth2-client: Privilege Escalation in
spring-security-oauth2-client (CVE-2022-31690)

* xstream: Denial of Service by injecting recursive collections or maps
based on element's hash values raising a stack overflow (CVE-2022-41966)

* Apache CXF: SSRF Vulnerability (CVE-2022-46364)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2155682 - CVE-2022-46364 Apache CXF: SSRF Vulnerability
2162200 - CVE-2022-31690 spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client
2170431 - CVE-2022-41966 xstream: Denial of Service by injecting recursive collections or maps based on element's hash values raising a stack overflow

5. References:

https://access.redhat.com/security/cve/CVE-2021-46848
https://access.redhat.com/security/cve/CVE-2022-2056
https://access.redhat.com/security/cve/CVE-2022-2057
https://access.redhat.com/security/cve/CVE-2022-2058
https://access.redhat.com/security/cve/CVE-2022-2519
https://access.redhat.com/security/cve/CVE-2022-2520
https://access.redhat.com/security/cve/CVE-2022-2521
https://access.redhat.com/security/cve/CVE-2022-2867
https://access.redhat.com/security/cve/CVE-2022-2868
https://access.redhat.com/security/cve/CVE-2022-2869
https://access.redhat.com/security/cve/CVE-2022-2953
https://access.redhat.com/security/cve/CVE-2022-4415
https://access.redhat.com/security/cve/CVE-2022-31690
https://access.redhat.com/security/cve/CVE-2022-35737
https://access.redhat.com/security/cve/CVE-2022-40303
https://access.redhat.com/security/cve/CVE-2022-40304
https://access.redhat.com/security/cve/CVE-2022-41966
https://access.redhat.com/security/cve/CVE-2022-42010
https://access.redhat.com/security/cve/CVE-2022-42011
https://access.redhat.com/security/cve/CVE-2022-42012
https://access.redhat.com/security/cve/CVE-2022-43680
https://access.redhat.com/security/cve/CVE-2022-46364
https://access.redhat.com/security/cve/CVE-2022-47629
https://access.redhat.com/security/cve/CVE-2023-21835
https://access.redhat.com/security/cve/CVE-2023-21843
https://access.redhat.com/security/updates/classification/#important

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBZBMyj9zjgjWX9erEAQjYeQ//UuRPtn96y1y86Oy3h22AOmgbhm+14j0E
QdVf/7R+cdOrhTh/U8Q0J+TyB69aqqFkPkt13hK55C6/GR+BF3hxsmEeYPEU09XA
4b0lfu9Wx+o707zPB6PRhMA8nNAnXfkeu9LNGSHY/jLBug6KXSlyQ9/h0HWB4j19
xFdUUlfW2wDjzV8j697garKk6oGY+3VOMF3RbD35EWCSOdLrX3aY+tsqunk0dCMJ
GE7uHxqoDtYNWnQAQnd4gCydhl1RRGq2tzY1OClEZ4/zpFQWs3nLIkeUCGs+mCfk
gp8tz+/zyytxSa/Oweak6Z50UC2qlYonPAH8883E181un0vq2NMeJdNlBzPnlO3P
ebUZgoS1jE07BN/rack9NBUjnTQ8t/vpeDavjjhQPgjsiSUcrQwSR4YhckbKz07B
muvOo6vz645punZ+BwYMvjT9XAR9Tx5JfuureeQOVvi3iiGgiR4cfreKXX/Xt2gh
/7ALcDeV05P41SN6d+z7fvEaXpdYwSs2H4Wbf+oEpV9FUockEElrYSOYrZVQ6Muh
H6m/hboerV8SBn3JrM3egj+sXZw4pCitrotFQB1HM6/duS5uY0m0dDAaCR8DCJcL
qV6cNHOBjtXYAxxextdcrbF+IwoGWDrOuifIL2OSQgT/Qvh0AaSAWe+FCNPHfIJY
MW3fEoqdc88=4fmY
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-1286:01 Important: Migration Toolkit for Runtimes

Migration Toolkit for Runtimes 1.0.2 release Red Hat Product Security has rated this update as having a security impact of Important

Summary

Migration Toolkit for Runtimes 1.0.2 Images
Security Fix(es):
* spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client (CVE-2022-31690)
* xstream: Denial of Service by injecting recursive collections or maps based on element's hash values raising a stack overflow (CVE-2022-41966)
* Apache CXF: SSRF Vulnerability (CVE-2022-46364)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2021-46848 https://access.redhat.com/security/cve/CVE-2022-2056 https://access.redhat.com/security/cve/CVE-2022-2057 https://access.redhat.com/security/cve/CVE-2022-2058 https://access.redhat.com/security/cve/CVE-2022-2519 https://access.redhat.com/security/cve/CVE-2022-2520 https://access.redhat.com/security/cve/CVE-2022-2521 https://access.redhat.com/security/cve/CVE-2022-2867 https://access.redhat.com/security/cve/CVE-2022-2868 https://access.redhat.com/security/cve/CVE-2022-2869 https://access.redhat.com/security/cve/CVE-2022-2953 https://access.redhat.com/security/cve/CVE-2022-4415 https://access.redhat.com/security/cve/CVE-2022-31690 https://access.redhat.com/security/cve/CVE-2022-35737 https://access.redhat.com/security/cve/CVE-2022-40303 https://access.redhat.com/security/cve/CVE-2022-40304 https://access.redhat.com/security/cve/CVE-2022-41966 https://access.redhat.com/security/cve/CVE-2022-42010 https://access.redhat.com/security/cve/CVE-2022-42011 https://access.redhat.com/security/cve/CVE-2022-42012 https://access.redhat.com/security/cve/CVE-2022-43680 https://access.redhat.com/security/cve/CVE-2022-46364 https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/cve/CVE-2023-21835 https://access.redhat.com/security/cve/CVE-2023-21843 https://access.redhat.com/security/updates/classification/#important

Package List


Severity
Advisory ID: RHSA-2023:1286-01
Product: Migration Toolkit for Runtimes
Advisory URL: https://access.redhat.com/errata/RHSA-2023:1286
Issued Date: : 2023-03-16
CVE Names: CVE-2021-46848 CVE-2022-2056 CVE-2022-2057 CVE-2022-2058 CVE-2022-2519 CVE-2022-2520 CVE-2022-2521 CVE-2022-2867 CVE-2022-2868 CVE-2022-2869 CVE-2022-2953 CVE-2022-4415 CVE-2022-31690 CVE-2022-35737 CVE-2022-40303 CVE-2022-40304 CVE-2022-41966 CVE-2022-42010 CVE-2022-42011 CVE-2022-42012 CVE-2022-43680 CVE-2022-46364 CVE-2022-47629 CVE-2023-21835 CVE-2023-21843

Topic

Migration Toolkit for Runtimes 1.0.2 releaseRed Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2155682 - CVE-2022-46364 Apache CXF: SSRF Vulnerability

2162200 - CVE-2022-31690 spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client

2170431 - CVE-2022-41966 xstream: Denial of Service by injecting recursive collections or maps based on element's hash values raising a stack overflow


Related News