RHSA-2024:1925MediumCVSS 6.5

Red Hat Security Advisory: Migration Toolkit for Containers (MTC) 1.8.3 security and bug fix update

Published
April 18, 2024
Last Modified
September 20, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-45857 — axios: exposure of confidential data stored in cookies CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON

🎯 Affected products12

  • 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-controller-rhel8@sha256:f8bb40b67361ce71c049a6c01480b121654e1dbdeb6d4e0de083139799ec896f_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-hook-runner-rhel8@sha256:b23a8caf24c7006abd0b60d30d0274f65c3e246ee9afa4172dbdfcfdb1ab1f56_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-log-reader-rhel8@sha256:cf04aecf798695488d782ab240539c6c76ded0e392db812d7a1e81194d6713f5_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-must-gather-rhel8@sha256:41ed4c8a0c1a6730b328eeba4a83fb128a5bffc3549a74375c512d87edf305e2_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-openvpn-rhel8@sha256:352748648fdb5c8fd3e70c893ece3577e197c98ee668a85273ad0039b652f3f3_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-operator-bundle@sha256:49b4655b2b31844f4732b8bff1e01b3ca038b6635665caf23cf747790c6074c6_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-registry-rhel8@sha256:cfbf428a046ca3e673fe10fe4df989c8a286e9e7eaa9461eaa2b09d8c9332292_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-rhel8-operator@sha256:5a0ee2242345f67c5c51d1ca75e6d9a1893676bcea84759b4a6a4282d47d0066_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:b0f5036015c0b272e403e706ab40e2cdc3b76072cdb0c5bef0cc1531dc6901fc_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-ui-rhel8@sha256:902ba355ec98d5d07c8994f0a7897ce1403dad657d6c8e3aa9a0d7adcbcec515_amd64 as a component of 8Base-RHMTC-1.8
  • rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8@sha256:17d30fd60779b7709db3ed321a44f030ff52c2755c56b25fa3931481c7679ee1_amd64 as a component of 8Base-RHMTC-1.8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (7)