RHSA-2023:0934HighCVSS 8.8

Red Hat Security Advisory: Migration Toolkit for Applications security and bug fix update

Published
February 28, 2023
Last Modified
May 27, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2020-36567 — gin: Unsanitized input in the default logger in github.com/gin-gonic/gin CVE-2021-35065 — glob-parent: Regular Expression Denial of Service CVE-2022-24999 — express: "qs" prototype poisoning causes the hang of the node process CVE-2022-37601 — loader-utils: prototype pollution in function parseQuery in parseQuery.js CVE-2022-37603 — loader-utils: Regular expression denial of service CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests CVE-2022-42920 — Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing CVE-2022-46175 — json5: Prototype Pollution in JSON5 via Parse Method

🔗 References (33)