RHSA-2024:3920: Important: Migration Toolkit for Runtimes security, bug fix and enhancement update
Important: Migration Toolkit for Runtimes security, bug fix and enhancement update
Other sources
Migration Toolkit for Runtimes 1.2.6 ZIP artifactsSecurity Fix(es): axios: exposure of confidential data stored in cookies (CVE-2023-45857) follow-redirects: Possible credential leak (CVE-2024-28849) commons-configuration2: various flaws (CVE-2024-29131) commons-configuration2: various flaws (CVE-2024-29133) webpack-dev-middleware: lack of URL validation may lead to file leak (CVE-2024-29180) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3920?
The severity of RHSA-2024:3920 is classified as Important.
What vulnerabilities are addressed in RHSA-2024:3920?
RHSA-2024:3920 addresses vulnerabilities including CVE-2023-45857 related to axios and possible credential leakage in follow-redirects.
How do I fix RHSA-2024:3920?
To fix RHSA-2024:3920, users should update to the latest version of Migration Toolkit for Runtimes as specified in the advisory.
Which software is affected by RHSA-2024:3920?
RHSA-2024:3920 affects the Red Hat Migration Toolkit for Runtimes.
Is there a recommended action for RHSA-2024:3920?
It is recommended to apply the security updates provided in RHSA-2024:3920 to mitigate the identified vulnerabilities.