Red Hat Security Advisory: Migration Toolkit for Containers (MTC) 1.8.4 security and bug fix update
🔗 CVE IDs covered (13)
📋 Description
CVE-2019-25211 — github.com/gin-contrib/cors: Gin mishandles a wildcard in the origin string in github.com/gin-contrib/cors CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-45289 — golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-4068 — braces: fails to limit the number of characters it can handle CVE-2024-24788 — golang: net: malformed DNS message can cause infinite loop CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-28849 — follow-redirects: Possible credential leak CVE-2024-28863 — node-tar: denial of service while parsing a tar file due to lack of folders depth validation CVE-2024-29018 — moby: external DNS requests from 'internal' networks could lead to data exfiltration CVE-2024-29041 — express: cause malformed URLs to be evaluated CVE-2024-29180 — webpack-dev-middleware: lack of URL validation may lead to file leak CVE-2024-39338 — axios: axios: Server-Side Request Forgery
🎯 Affected products12
- 8Base-RHMTC-1.8
- rhmtc/openshift-migration-controller-rhel8@sha256:a4025dfcd79bcb22e2ab91e1bc027c200f9c2741ed2c3a576a64cb24084c584e_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-hook-runner-rhel8@sha256:419c11ecd25664d16f77aec6589c9fa183832947766f75575dfab4bc059fe876_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-log-reader-rhel8@sha256:6886c4d68d7c6100b5eb7239ae8ce14871403a71ce69b35c42c0ce238b32ff87_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-must-gather-rhel8@sha256:08bb8048bb9fc00ba84e846fce7ce3e37506fbadf077b487c1d3d2dd607b2277_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-openvpn-rhel8@sha256:1e0cf80fab89615624cf7f9f62e72e161af4143ed1d6245db45f09ba8382dbc4_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-operator-bundle@sha256:9616b52c1d745b7bf37c0237a6cd2cde9a1d9e8dbfdb5e5cb49504805e706065_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-registry-rhel8@sha256:c7f229ac51306d667f9b766fb1a464686fa47eb06d5658dbe4977e25b4877b20_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-rhel8-operator@sha256:79c957509adaff575917d1e70ec25965a4230c0a2deb9cd9007089dfc3ec39cc_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:b556472a46fbac2508b8f36b975c8fdb26a77a2fc8bd43b2667f9151bf1cbc3f_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-ui-rhel8@sha256:db4903f395697e2eb244a0251ec1a5f89b12434501cb56889f2af37770f95f58_amd64 as a component of 8Base-RHMTC-1.8
- rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8@sha256:8765eb907963a6677c1af44dee1168d635d243824396f73c829697b1582046e9_amd64 as a component of 8Base-RHMTC-1.8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2024:7164
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268018
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269576
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270863
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274767
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2279814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2280600
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2290901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293200
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295302
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2299624
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2299625
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2299628
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2299668
- externalhttps://issues.redhat.com/browse/MIG-1592
- externalhttps://issues.redhat.com/browse/MIG-1593
- externalhttps://issues.redhat.com/browse/MIG-1598
- externalhttps://issues.redhat.com/browse/MIG-1610
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7164.json