RHSA-2023:0934HighCVSS 8.8

Red Hat Security Advisory: Migration Toolkit for Applications security and bug fix update

Published
February 28, 2023
Last Modified
August 19, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2020-36567 — gin: Unsanitized input in the default logger in github.com/gin-gonic/gin CVE-2021-35065 — glob-parent: Regular Expression Denial of Service CVE-2022-24999 — express: "qs" prototype poisoning causes the hang of the node process CVE-2022-37601 — loader-utils: prototype pollution in function parseQuery in parseQuery.js CVE-2022-37603 — loader-utils: Regular expression denial of service CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests CVE-2022-42920 — Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing CVE-2022-46175 — json5: Prototype Pollution in JSON5 via Parse Method

🎯 Affected products6

  • MTA 6.0 for RHEL 8
  • mta/mta-admin-addon-rhel8@sha256:9445191232ad1ff1c2926b5a2194130502696a74620cda941675edc9c366b305_amd64 as a component of MTA 6.0 for RHEL 8
  • mta/mta-hub-rhel8@sha256:ebc8706761a518bd08447a6e51a35f81e5beb3840f3b6b66f656c23c36c07e76_amd64 as a component of MTA 6.0 for RHEL 8
  • mta/mta-pathfinder-rhel8@sha256:b50244562f83977574d1bd88adc1d259501c90f883596b15fa81e557844e2956_amd64 as a component of MTA 6.0 for RHEL 8
  • mta/mta-ui-rhel8@sha256:e00e79bc7fb1bc104b1d3e0ebc6b49c7d3c7885925e3c432d60b43f10aaec1c4_amd64 as a component of MTA 6.0 for RHEL 8
  • mta/mta-windup-addon-rhel8@sha256:9a912e054a7c46e07bdbfeb165f0e71ff3686bcdba9cd53d0ed6be8ff0607108_amd64 as a component of MTA 6.0 for RHEL 8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (33)