RHSA-2024:3919: Important: Migration Toolkit for Runtimes security, bug fix and enhancement update
Important: Migration Toolkit for Runtimes security, bug fix and enhancement update
Other sources
Migration Toolkit for Runtimes 1.2.6 ImagesSecurity Fix(es): undertow: Cookie Smuggling/Spoofing (CVE-2023-4639) jetty: Improper addition of quotation marks to user inputs in CgiServlet (CVE-2023-36479) css-tools: Improper Input Validation causes Denial of Service via Regular Expression (CVE-2023-26364) css-tools: regular expression denial of service (ReDoS) when parsing CSS (CVE-2023-48631) keycloak: path transversal in redirection validation (CVE-2024-1132) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3919?
RHSA-2024:3919 is classified as important due to the security, bug fixes, and enhancements it provides.
How do I fix RHSA-2024:3919?
To fix RHSA-2024:3919, update the Red Hat Migration Toolkit for Runtimes to version 1.2.6.
What vulnerabilities are addressed in RHSA-2024:3919?
RHSA-2024:3919 addresses vulnerabilities related to cookie smuggling/spoofing (CVE-2023-4639) and improper handling of user inputs in CgiS.
What products are affected by RHSA-2024:3919?
RHSA-2024:3919 affects the Red Hat Migration Toolkit for Runtimes.
Is there a workaround for RHSA-2024:3919?
There are no known workarounds for the vulnerabilities addressed in RHSA-2024:3919; the recommended action is to apply the update.