RHBA-2024:1440HighCVSS 9.8
Red Hat Bug Fix Advisory: MTV 2.5.6 Images
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39326 — golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests CVE-2023-42282 — nodejs-ip: arbitrary code execution via the isPublic() function
🎯 Affected products15
- 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-api-rhel9@sha256:0f4e01423ae4c7a6f825f2373c7766f78f12aba02d7521f20c57b7d8ab595c90_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:870717b17d1277d8b91b2cad27713d43043fa968babbbb96ab1bb76328f316bb_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-controller-rhel9@sha256:d0b80c42d50f35a897c1f6194bb945d39ead87d4f75e9b8749b445652b854118_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-must-gather-api-rhel8@sha256:2705373c12a52a6381c7eaec7de49926d27ef001230cd185b5a1bc69e10c353b_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:3280cc7d7e3ef235d92b0b094868438c474f88ac10ffc0bf8b5a62db02003c63_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:48c96f917696e7e6fae056f60ca1c296e99cfc12d2306fd706c5eacc65a14c5c_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-operator-bundle@sha256:9d5aaf522aed32d5e63948e2ce9359d99603829aed91c3e0da2c529f555fec91_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:981bee1559e7aca484f39fb46e5c1b7c54e0ff1ce74f1662a83e0ff4951f2dff_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:45bc8de023bbdae27728c7756a5f701ea2c68f359aa1d0dac70040021465d82e_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-rhel8-operator@sha256:81a9daf048f6e4ff96d50e19df354f695d50724cec047981161b51e9bd3ac212_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:8f94983a110597a7bade03a71b45ace8fb7ad140d9e1729f5fb6b329802d7413_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-validation-rhel9@sha256:9f8b478fd28d214c2ddb28d892d1f3869d3a454ca664baa4a7657f420d55f942_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:43276cd2620b7b75f3e1ec1741f7ed252246085c841f479dcc2e132d868d33ca_amd64 as a component of 8Base-MTV-2.5
- migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:73cc6a3adbcce881ebe41aa3dbb27be1c85d9c0d2ff0533c83481db780449d7c_amd64 as a component of 8Base-MTV-2.5
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is available for this flaw. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.