Red Hat Security Advisory: Migration Toolkit for Applications security and bug fix update
🔗 CVE IDs covered (14)
📋 Description
CVE-2023-26159 — follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() CVE-2023-26364 — css-tools: Improper Input Validation causes Denial of Service via Regular Expression CVE-2023-36479 — jetty: Improper addition of quotation marks to user inputs in CgiServlet CVE-2023-45857 — axios: exposure of confidential data stored in cookies CVE-2023-48631 — css-tools: regular expression denial of service (ReDoS) when parsing CSS CVE-2024-1023 — io.vertx/vertx-core: memory leak due to the use of Netty FastThreadLocal data structures in Vertx CVE-2024-1132 — keycloak: path transversal in redirection validation CVE-2024-1300 — io.vertx:vertx-core: memory leak when a TCP server is configured with TLS and SNI support CVE-2024-25710 — commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file CVE-2024-26308 — commons-compress: OutOfMemoryError unpacking broken Pack200 file CVE-2024-28849 — follow-redirects: Possible credential leak CVE-2024-29131 — commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator() CVE-2024-29133 — commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree CVE-2024-29180 — webpack-dev-middleware: lack of URL validation may lead to file leak
🎯 Affected products7
- MTA 6.2 for RHEL 8
- mta/mta-hub-rhel9@sha256:325bec37f1ab499f8ae0abb38ca3929f66a0fe63b6ebdf60a1cdc3bbd79ad25e_amd64 as a component of MTA 6.2 for RHEL 8
- mta/mta-operator-bundle@sha256:a13643117c2867351718a872f7f1b2350c67855ca73a727a1dc140754ffe6589_amd64 as a component of MTA 6.2 for RHEL 8
- mta/mta-pathfinder-rhel9@sha256:851d4890717247af6aa9b0b6da9be95fe8aeb70183834e9de15a4302c487b9f0_amd64 as a component of MTA 6.2 for RHEL 8
- mta/mta-rhel8-operator@sha256:f588b869c3f273eb20c4c80a9aa5acd4a84c56c1dd85429a39a7d2d60f28d41e_amd64 as a component of MTA 6.2 for RHEL 8
- mta/mta-ui-rhel9@sha256:0e0167affe099168142b9ebdce5520e972dea63ff6c7f3cda48e0bb4ae4cd0ec_amd64 as a component of MTA 6.2 for RHEL 8
- mta/mta-windup-addon-rhel9@sha256:7884928eb3d01d4f9c8b5463ef9f6cec7d7df4d669e6d30cafe05af60202b003_amd64 as a component of MTA 6.2 for RHEL 8
✅ Remediation
For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is yet available for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No current mitigation is available for this vulnerability. Workaround: No mitigation is currently available for this vulnerability.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2024:3989
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239630
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2248979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254559
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256413
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2260840
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262117
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2263139
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264988
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264989
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269576
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270673
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270674
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270863
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3989.json