Red Hat Security Advisory: Migration Toolkit for Applications security and bug fix update
🔗 CVE IDs covered (8)
📋 Description
CVE-2020-36567 — gin: Unsanitized input in the default logger in github.com/gin-gonic/gin CVE-2021-35065 — glob-parent: Regular Expression Denial of Service CVE-2022-24999 — express: "qs" prototype poisoning causes the hang of the node process CVE-2022-37601 — loader-utils: prototype pollution in function parseQuery in parseQuery.js CVE-2022-37603 — loader-utils: Regular expression denial of service CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests CVE-2022-42920 — Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing CVE-2022-46175 — json5: Prototype Pollution in JSON5 via Parse Method
🎯 Affected products6
- MTA 6.0 for RHEL 8
- mta/mta-admin-addon-rhel8@sha256:9445191232ad1ff1c2926b5a2194130502696a74620cda941675edc9c366b305_amd64 as a component of MTA 6.0 for RHEL 8
- mta/mta-hub-rhel8@sha256:ebc8706761a518bd08447a6e51a35f81e5beb3840f3b6b66f656c23c36c07e76_amd64 as a component of MTA 6.0 for RHEL 8
- mta/mta-pathfinder-rhel8@sha256:b50244562f83977574d1bd88adc1d259501c90f883596b15fa81e557844e2956_amd64 as a component of MTA 6.0 for RHEL 8
- mta/mta-ui-rhel8@sha256:e00e79bc7fb1bc104b1d3e0ebc6b49c7d3c7885925e3c432d60b43f10aaec1c4_amd64 as a component of MTA 6.0 for RHEL 8
- mta/mta-windup-addon-rhel8@sha256:9a912e054a7c46e07bdbfeb165f0e71ff3686bcdba9cd53d0ed6be8ff0607108_amd64 as a component of MTA 6.0 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (33)
- selfhttps://access.redhat.com/errata/RHSA-2023:0934
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134876
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2140597
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2142707
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150323
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156263
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156324
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156683
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://issues.redhat.com/browse/MTA-103
- externalhttps://issues.redhat.com/browse/MTA-106
- externalhttps://issues.redhat.com/browse/MTA-122
- externalhttps://issues.redhat.com/browse/MTA-123
- externalhttps://issues.redhat.com/browse/MTA-127
- externalhttps://issues.redhat.com/browse/MTA-131
- externalhttps://issues.redhat.com/browse/MTA-36
- externalhttps://issues.redhat.com/browse/MTA-44
- externalhttps://issues.redhat.com/browse/MTA-49
- externalhttps://issues.redhat.com/browse/MTA-59
- externalhttps://issues.redhat.com/browse/MTA-65
- externalhttps://issues.redhat.com/browse/MTA-72
- externalhttps://issues.redhat.com/browse/MTA-73
- externalhttps://issues.redhat.com/browse/MTA-74
- externalhttps://issues.redhat.com/browse/MTA-76
- externalhttps://issues.redhat.com/browse/MTA-77
- externalhttps://issues.redhat.com/browse/MTA-80
- externalhttps://issues.redhat.com/browse/MTA-82
- externalhttps://issues.redhat.com/browse/MTA-85
- externalhttps://issues.redhat.com/browse/MTA-88
- externalhttps://issues.redhat.com/browse/MTA-92
- externalhttps://issues.redhat.com/browse/MTA-96
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0934.json