Red Hat Security Advisory: Migration Toolkit for Containers (MTC) 1.7.15 security and bug fix update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28180 — jose-go: improper handling of highly compressed data
🎯 Affected products18
- 8Base-RHMTC-1.7
- rhmtc/openshift-migration-controller-rhel8@sha256:c312ff737af8d68dd54d16478940ec45b263aeafae10692d1b415b67e4ff85dd_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-hook-runner-rhel8@sha256:efe71724a81189dd6f32790706f4412c6e3705c78586bfc87bbd7a439c45e982_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-legacy-rhel8-operator@sha256:75107be29b4092fd644436000bff239dbfe9f4c5a4abb039737202bf14e73ca4_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-log-reader-rhel8@sha256:c5b5d49ca6f6a00b5d1afa289df8d80ce016ae31ab9e5e5df5fc0e1aa2410fcf_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-must-gather-rhel8@sha256:12c15fb95fb9928172bd0a7fed31e1fc95a360a56db958df88fe4368bbd6f463_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-openvpn-rhel8@sha256:d6d4e2c3717f82bd85d81f8992bbb81c30f5423ce4a9c2c781f3f13f4fcf7d2a_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-operator-bundle@sha256:1b1f273e6ed2300ca64962f18a0402bba8a60c0629bb94da6aa16b90986ee558_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-registry-rhel8@sha256:dda43dae1989c7f55471990df74b48584dc0789d1c94ce8cec7c9c06e134ddc8_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-rhel8-operator@sha256:d5f8a6eea65665dfc14d7f6b8700c984720a0663ff15325ada113f39dc79fa77_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:d128bd063bae38f4a7405932ccf1f71a00deeea8fcae9ac86889556444c90bc1_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-ui-rhel8@sha256:39500437728e982296795d9e116a772221ec1f36d357d01918b82abf97b3aaa2_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-velero-plugin-for-aws-rhel8@sha256:3452d0015f671f42d1282d7843f0511be7b3c218596d966dbe124203e4269530_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-velero-plugin-for-gcp-rhel8@sha256:2749cf7874d8b93ea1a3840057328857c94531f65d1034909a36bb49afccb7a2_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8@sha256:f6e3192d3e604e7b01e58e3dd8ecb16d93e4c7766c50b5b835256b9e55a36347_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-velero-restic-restore-helper-rhel8@sha256:d629598125de25b737c5a3e89b7c00716e83d1953a9d8b5bde802df07af8c1ee_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-migration-velero-rhel8@sha256:1af9e6a419b14dbeaa3953fcd69a34ca4a52d23ea5c021d06ca836054a4308c5_amd64 as a component of 8Base-RHMTC-1.7
- rhmtc/openshift-velero-plugin-rhel8@sha256:9d7b7894a61cb8e3a1037c1b874f3122ccc1dafc86b657bedf68350fde9ac0b8_amd64 as a component of 8Base-RHMTC-1.7
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:2639
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2639.json