-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Migration Toolkit for Runtimes security update
Advisory ID:       RHSA-2023:3813-01
Product:           Migration Toolkit for Runtimes
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:3813
Issue date:        2023-06-27
CVE Names:         CVE-2021-3782 CVE-2022-3627 CVE-2022-3970 
                   CVE-2022-4492 CVE-2022-36227 CVE-2023-0361 
                   CVE-2023-2491 CVE-2023-27535 
====================================================================
1. Summary:

An update for mtr-operator-bundle-container, mtr-operator-container,
mtr-web-container, and mtr-web-executor-container is now available for
Migration Toolkit for Runtimes 1 on RHEL 8.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Migration Toolkit for Runtimes 1.1.1 Images

Security Fix(es):

* undertow: Server identity in https connection is not checked by the
undertow client (CVE-2022-4492)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2153260 - CVE-2022-4492 undertow: Server identity in https connection is not checked by the undertow client

5. References:

https://access.redhat.com/security/cve/CVE-2021-3782
https://access.redhat.com/security/cve/CVE-2022-3627
https://access.redhat.com/security/cve/CVE-2022-3970
https://access.redhat.com/security/cve/CVE-2022-4492
https://access.redhat.com/security/cve/CVE-2022-36227
https://access.redhat.com/security/cve/CVE-2023-0361
https://access.redhat.com/security/cve/CVE-2023-2491
https://access.redhat.com/security/cve/CVE-2023-27535
https://access.redhat.com/security/updates/classification/#moderate

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBZJsFrNzjgjWX9erEAQjqvBAAgwT2yGcVY1aE8h9lrW8X4Dmb4Yq65hVm
0Qk6n0BjmDT5kne1VBWwJPyE+oAiLVDmnBI1quqARSmMVZoQVQpcNImwLF0A5pU9
8xfSvVnaKp7x3fEoxE5gXUQd9z4N7osKtZLg0xvTeHo2ip4BxSpKvyu8TDjorPUk
YXOkMxi1YZX180suGio4Rtp5GNwOVNdpvLu4o+/XUKzREHVAI6VbB5DI12Joy5I0
BeQkEkxAWQ6tIh9WIr0QSK82T0f1xsQFNG/tzrNbtRKbcOyiiiv15MINrLFufmLY
hbxslHSxsFdur8GC6VbsPfMdPDMI3MgMnSYH+2GTz7zalVAIntbfwoWfaJ7b5ZWw
bP/oohbKuTzGCcWZn2PpqjAPajS00DJTWL8q9EH44PGUv48qS2sDjFyWp6xtNyCp
ceDOD56qFECZ6hO9STUwJ4pyJPVRI+2+OVzgMaqkQPHAfo6tKv6DJ9BXuWuGdf7g
5lKDHRhLT8sDNHU91rbjYT31sqiE14jHkseZ8jSExMFJGtwN9gVJmCRxwjPzJuJV
4hPh5otnYfHeq7jZ4Ra/aUDzeBxVl6w1j3CCGtEaypyZ51hTu5QRzsZ1KyIPQH09
mrX2H+a9uSkLU+KGyNe1fwKmIVAQca9s+C5SLdmgEFRwAMntCBF5oRSm30xlas9T
Clr44cObnDs=Yq4r
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-3813:01 Moderate: Migration Toolkit for Runtimes security

An update for mtr-operator-bundle-container, mtr-operator-container, mtr-web-container, and mtr-web-executor-container is now available for Migration Toolkit for Runtimes 1 on RHEL...

Summary

Migration Toolkit for Runtimes 1.1.1 Images
Security Fix(es):
* undertow: Server identity in https connection is not checked by the undertow client (CVE-2022-4492)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2021-3782 https://access.redhat.com/security/cve/CVE-2022-3627 https://access.redhat.com/security/cve/CVE-2022-3970 https://access.redhat.com/security/cve/CVE-2022-4492 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-2491 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/updates/classification/#moderate

Package List


Severity
Advisory ID: RHSA-2023:3813-01
Product: Migration Toolkit for Runtimes
Advisory URL: https://access.redhat.com/errata/RHSA-2023:3813
Issued Date: : 2023-06-27
CVE Names: CVE-2021-3782 CVE-2022-3627 CVE-2022-3970 CVE-2022-4492 CVE-2022-36227 CVE-2023-0361 CVE-2023-2491 CVE-2023-27535

Topic

An update for mtr-operator-bundle-container, mtr-operator-container,mtr-web-container, and mtr-web-executor-container is now available forMigration Toolkit for Runtimes 1 on RHEL 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2153260 - CVE-2022-4492 undertow: Server identity in https connection is not checked by the undertow client


Related News