First published: Thu Jul 11 2024(Updated: )
The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API.<br>Security Fix(es) from Bugzilla:<br><li> webpack-dev-middleware: lack of URL validation may lead to file leak (CVE-2024-29180)</li> <li> golang: net/<a href="http:" target="_blank">http:</a> memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)</li> <li> golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783)</li> <li> golang: net/mail: comments in display names are incorrectly handled (CVE-2024-24784)</li> <li> golang: html/template: errors returned from MarshalJSON methods may break template escaping (CVE-2024-24785)</li> <li> envoy: HTTP/2 CPU exhaustion due to CONTINUATION frame flood (CVE-2024-30255)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Migration Toolkit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:4520 is rated as a moderate security vulnerability.
To fix RHSA-2024:4520, update the Migration Toolkit for Containers to the latest version provided by Red Hat.
RHSA-2024:4520 affects the Red Hat Migration Toolkit for Containers.
RHSA-2024:4520 addresses security vulnerabilities that impact the Migration Toolkit for Containers.
RHSA-2024:4520 was released in 2024 as a security advisory from Red Hat.