Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

RHEL 8: RHSA-2023-3813 Moderate: Migration Toolkit Security Fixes

red hat
Calendar Grey June 27, 2023
Dist Redhat Esm H88
Notice: New update for Migration Toolkit for Runtimes classified as Moderate. Security patches released for RHEL 8 platforms.
An update for mtr-operator-bundle-container, mtr-operator-container, mtr-web-container, and mtr-web-executor-container is now available for Migration Toolkit for Runtimes 1 on RHEL...

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Migration Toolkit for Runtimes 1.1.1 Images
Security Fix(es):
* undertow: Server identity in https connection is not checked by the undertow client (CVE-2022-4492)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2021-3782 https://access.redhat.com/security/cve/CVE-2022-3627 https://access.redhat.com/security/cve/CVE-2022-3970 https://access.redhat.com/security/cve/CVE-2022-4492 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-2491 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/updates/classification/#moderate

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2023:3813-01
Product: Migration Toolkit for Runtimes
Issue date: 2023-06-27

Topic

An update for mtr-operator-bundle-container, mtr-operator-container,mtr-web-container, and mtr-web-executor-container is now available forMigration Toolkit for Runtimes 1 on RHEL 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2153260 - CVE-2022-4492 undertow: Server identity in https connection is not checked by the undertow client

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here