Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

RedHat: 2023:1428-01 Important Migration Toolkit Update, DoS Threat

red hat
Calendar Grey March 23, 2023
Dist Redhat Esm H88
Significant release for Migration Toolkit for Containers (MTC) version 1.7.8 features critical security enhancements and various bug resolutions.
The Migration Toolkit for Containers (MTC) 1.7.8 is now available

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API.
Security Fix(es):
* decode-uri-component: improper input validation resulting in DoS (CVE-2022-38900)
* gin: Unsanitized input in the default logger in github.com/gin-gonic/gin (CVE-2020-36567)
* express: "qs" prototype poisoning causes the hang of the node process (CVE-2022-24999)
* http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability (CVE-2022-25881)
* ua-parser-js: ReDoS vulnerability via the trim() function (CVE-2022-25927)
* loader-utils: Regular expression denial of service (CVE-2022-37603)
* json5: Prototype Pollution in JSON5 via Parse Method (CVE-2022-46175)
* jszip: directory traversal via a crafted ZIP archive (CVE-2022-48285)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* The velero image cannot be overridden in the operator (BZ#2143389)
* Adding a MigCluster from UI fails when the domain name has charactersmore than 6 (BZ#2152149)
* UI fails to render the 'migrations' page: "Cannot read properties of undefined (reading 'name')" (BZ#2163485)
* Creating DPA resource fails on OCP 4.6 clusters (BZ#2173742)

References

https://access.redhat.com/security/cve/CVE-2020-10735 https://access.redhat.com/security/cve/CVE-2020-36567 https://access.redhat.com/security/cve/CVE-2021-4235 https://access.redhat.com/security/cve/CVE-2021-28861 https://access.redhat.com/security/cve/CVE-2022-1705 https://access.redhat.com/security/cve/CVE-2022-2879 https://access.redhat.com/security/cve/CVE-2022-2880 https://access.redhat.com/security/cve/CVE-2022-2995 https://access.redhat.com/security/cve/CVE-2022-3162 https://access.redhat.com/security/cve/CVE-2022-3172 https://access.redhat.com/security/cve/CVE-2022-3259 https://access.redhat.com/security/cve/CVE-2022-3466 https://access.redhat.com/security/cve/CVE-2022-4415 https://access.redhat.com/security/cve/CVE-2022-23521 https://access.redhat.com/security/cve/CVE-2022-24999 https://access.redhat.com/security/cve/CVE-2022-25881 https://access.redhat.com/security/cve/CVE-2022-25927 https://access.redhat.com/security/cve/CVE-2022-27664 https://access.redhat.com/security/cve/CVE-2022-30631 https://access.redhat.com/security/cve/CVE-2022-32148 https://access.redhat.com/security/cve/CVE-2022-32189 https://access.redhat.com/security/cve/CVE-2022-32190 https://access.redhat.com/security/cve/CVE-2022-37603 Read the Full Advisory

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2023:1428-01
Product: Red Hat Migration Toolkit
Issue date: 2023-03-23

Topic

The Migration Toolkit for Containers (MTC) 1.7.8 is now available.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2140597 - CVE-2022-37603 loader-utils:Regular expression denial of service

2143389 - The velero image cannot be overridden in the operator

2150323 - CVE-2022-24999 express: "qs" prototype poisoning causes the hang of the node process

2152149 - Adding a MigCluster from UI fails when the domain name has characters more than 6

2156263 - CVE-2022-46175 json5: Prototype Pollution in JSON5 via Parse Method

2156683 - CVE-2020-36567 gin: Unsanitized input in the default logger in github.com/gin-gonic/gin

2163485 - UI fails to render the 'migrations' page: "Cannot read properties of undefined ( reading 'name' )"

2165020 - CVE-2022-25927 ua-parser-js: ReDoS vulnerability via the trim() function

2165797 - CVE-2022-48285 jszip: directory traversal via a crafted ZIP archive

2165824 - CVE-2022-25881 http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability

2170644 - CVE-2022-38900 decode-uri-component: improper input validation resulting in DoS

2173742 - Creating DPA resource fails on OCP 4.6 clusters

5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):

MIG-1298 - Expand configuration SCC configuration options for rsync pod in DVM

MIG-1315 - Direct volume migration Rsync options are failing on validation

MIG-1318 - MTC 1.7.7 fails on OCP 4.12

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here