RHSA-2022:5483MediumCVSS 7.5
Red Hat Security Advisory: Migration Toolkit for Containers (MTC) 1.7.2 security and bug fix update
🔗 CVE IDs covered (3)
📋 Description
CVE-2021-3807 — nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes CVE-2022-0235 — node-fetch: exposure of sensitive information to an unauthorized actor CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak
🎯 Affected products17
- 8Base-RHMTC-1.7
- rhmtc/openshift-migration-controller-rhel8@sha256:12634213bd9cc156040443170c744d5d74bf0fbfc09a003fd24687265802315d_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-legacy-rhel8-operator@sha256:49c4d1d018cfe3cf36b1e32e3b5ff786d67032005a27a9f3918f94a0c43a2a16_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-log-reader-rhel8@sha256:6f882ba9232f847055af791246fbe9da70ffae4b478bc6a7bba90d7d21cf7946_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-must-gather-rhel8@sha256:aadfd9a92a70a1d18ebcdefe6c9ce9a8e7ab7e8b7d1a5e73a062d99d18997e0e_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-openvpn-rhel8@sha256:44309e4ecd3e796de6659864bd6aedac334d14ad1adf2ce65fe9ac1c9d889d91_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-operator-bundle@sha256:697a0375f3ff849b4b3d17c203ba8df25d194482655932de7af1bdd35b4cc07a_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-registry-rhel8@sha256:7ac7b18d9c211169962890a2333fd72974406dbd8942feb8c9df0e05929bbb7b_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-rhel8-operator@sha256:f54941290c1381334b4767a0e13d3e3f7c415f7391f676b70628d898d6ff4cb2_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:7240fbb6ab13949cbc48485e0c30b6e7082f4e0bd505173cf0c33926c98720d9_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-ui-rhel8@sha256:647fd52462128ba60ae9db9d3b1a8c3559dd944f43ca19126478d60d998bf029_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-velero-plugin-for-aws-rhel8@sha256:5e829c1a838510d26a31a4a6e459bb1daabf145a17e1df62dbf137dadd4cb5b8_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-velero-plugin-for-gcp-rhel8@sha256:3ca8294a9be3ca32a25f9083661fcae16a297a8cb487a9c30e9397f172f6edc9_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8@sha256:03191a4eba3db81aa04c6f28419b685ab4f877ef9db29997dac098cb900ce3b4_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-velero-restic-restore-helper-rhel8@sha256:b952ae7f6662ad82c054f213a19f243186059e787ae28243b504dd4f24a98610_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-velero-rhel8@sha256:f1e6241861004c7c0e4df612473e824bbb3431d85f25fa1b91e0889f511f504f_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-velero-plugin-rhel8@sha256:3ea042d0a976879d939ec0d669855590b5b0ef0735623b31b21b21b2c4091d4c_amd64 as a component of 8Base-RHMTC-1.7
✅ Remediation
For details on how to install and use MTC, refer to: https://docs.openshift.com/container-platform/latest/migration_toolkit_for_containers/installing-mtc.html
🔗 References (32)
- selfhttps://access.redhat.com/errata/RHSA-2022:5483
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2007557
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2038898
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040693
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2048537
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2055658
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056962
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2058172
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2058529
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2061335
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2062266
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2062862
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2074675
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2076593
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2076599
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2078459
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2079252
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2082221
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2082225
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088022
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088026
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089126
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089411
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089859
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2090317
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2096939
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2100486
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_5483.json