RHBA-2021:2854HighCVSS 9.8

Red Hat Bug Fix Advisory: Migration Toolkit for Containers (MTC) 1.4.6 release advisory

Published
July 21, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (23)

📋 Description

CVE-2018-25011 — libwebp: heap-based buffer overflow in PutLE16() CVE-2020-25648 — nss: TLS 1.3 CCS flood remote DoS Attack CVE-2020-25692 — openldap: NULL pointer dereference for unauthenticated packet in slapd CVE-2020-26541 — kernel: security bypass in certs/blacklist.c and certs/system_keyring.c CVE-2020-27216 — jetty: local temporary directory hijacking vulnerability CVE-2020-27218 — jetty: buffer not correctly recycled in Gzip Request inflation CVE-2020-27223 — jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS CVE-2020-36328 — libwebp: heap-based buffer overflow in WebPDecode*Into functions CVE-2020-36329 — libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c CVE-2021-3516 — libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c CVE-2021-3517 — libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c CVE-2021-3518 — libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c CVE-2021-3520 — lz4: memory corruption due to an integer overflow bug caused by memmove argument CVE-2021-3537 — libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode CVE-2021-3541 — libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms CVE-2021-20271 — rpm: Signature checks bypass via corrupted rpm package CVE-2021-21642 — jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. CVE-2021-21643 — jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. CVE-2021-21644 — jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability. CVE-2021-21645 — jenkins-2-plugins/config-file-provider: Does not perform permission checks in several HTTP endpoints. CVE-2021-27219 — glib: integer overflow in g_bytes_new function on 64-bit platforms due to an implicit cast from 64 bits to 32 bits CVE-2021-31525 — golang: net/http: panic in ReadRequest and ReadResponse when reading a very large header CVE-2021-33034 — kernel: use-after-free in net/bluetooth/hci_event.c when destroying an hci_chan

🎯 Affected products15

  • 7Server-RHMTC-1.4
  • 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-controller-rhel8@sha256:18574cc8e0805bc28bbb62724376ff468a986128d677dd23a552b3329c41858d_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-log-reader-rhel8@sha256:98e3601ef0f97c3c37ebc67a6f4af8ad5cd6d83596e3b120c9561b0b09d82ccf_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-must-gather-rhel8@sha256:ae2595c2aea186fce5ee5fdbd178ed26965bd421cc834a9ec2d162f4287add9d_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-operator-bundle@sha256:19f8a00034e63c8ed505b123ca224220695b043a825ffe55c32e5dd32dd05324_amd64 as a component of 7Server-RHMTC-1.4
  • rhmtc/openshift-migration-registry-rhel8@sha256:6c179703e3c9e1108a9265333834a24037f0f8142d9438fe2197c12b9eb4de0f_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:2c57a210641957a02149b5dcf96daab44cf7f35b57faf35e5b10bcafdb1091d9_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-ui-rhel8@sha256:ad6c9ecd4ebb45f7cdbfa1e3f750594f374845a4f4f2cad69007898e2953734d_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-velero-plugin-for-aws-rhel8@sha256:5c8e274d5821db1c6483b7c01549a265970ae7b0de23ac6faa2d354d566bdc39_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-velero-plugin-for-gcp-rhel8@sha256:3f486a14a1ea60f70116dd8791e0258cfc86e42948cb4aaeca56243bf37fe867_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8@sha256:4791f41741a2c701549791014c4e02431dd21f2358bc08141e405ba954b19e65_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-velero-restic-restore-helper-rhel8@sha256:12e9ea1273dd504e03a2034665141f7fc32bfef1117232c088f282916fef46fb_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-migration-velero-rhel8@sha256:47c7e9b2d4ef258a4551cfd55ae2a3c92fdb0a83f238e8ad2b404f1b834fd4a0_amd64 as a component of 8Base-RHMTC-1.4
  • rhmtc/openshift-velero-plugin-rhel8@sha256:6a360caa1ec8818d3c78d16709a8930a2c4fa696c15e557e2939de50e35859f1_amd64 as a component of 8Base-RHMTC-1.4

✅ Remediation

Before applying this update, ensure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 For details on how to install and use MTC, refer to: https://docs.openshift.com/container-platform/4.7/migration-toolkit-for-containers/installing-mtc.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Jetty users should create temp folders outside the normal /tmp structure, and ensure that their permissions are set so as not to be accessible by an attacker. Workaround: This flaw can be mitigated by not using xmllint with the --html and --push options together. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

🔗 References (5)