First published: Tue Jun 27 2023(Updated: )
Migration Toolkit for Runtimes 1.1.1 Images<br>Security Fix(es):<br><li> undertow: Server identity in https connection is not checked by the undertow client (CVE-2022-4492)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Migration Toolkit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:3813 is classified as moderate.
RHSA-2023:3813 addresses a vulnerability where the server identity in HTTPS connections is not checked by the Undertow client (CVE-2022-4492).
To fix RHSA-2023:3813, update to the latest version of Migration Toolkit for Runtimes as per Red Hat's guidance.
CVE-2022-4492 can lead to security risks as the client does not validate the server's identity in HTTPS connections.
Using affected versions poses a risk due to the vulnerability, and it is recommended to apply the security fix as soon as possible.