Important: Migration Toolkit for Applications security and bug fix update
Important: Migration Toolkit for Applications security and bug fix update
Migration Toolkit for Applications 7.0.2 Images<br>Security Fix(es) from Bugzilla:<br><li> golang: go/parser: stack exhaustion in all Parse functions (CVE-2022-1962)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Migration Toolkit for Applications Security Fix(es): golang: go/parser: stack exhaustion in all Parse functions (CVE-2022-1962) jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos (CVE-2022-45693) apache-ivy: XML External Entity vulnerability (CVE-2022-46751) jettison: Uncontrolled Recursion in JSONArray (CVE-2023-1436) guava: insecure temporary directory creation (CVE-2023-2976) follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() (CVE-2023-26159) golang: net/http: insufficient sanitization of Host header (CVE-2023-29406) golang: crypto/tls: slow verification of certificate chains containing large RSA keys (CVE-2023-29409) jackson-databind: denial of service via cylic dependencies (CVE-2023-35116) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Migration Toolkit for Applications 6.1.4 Images.Security Fix(es): golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: Migration Toolkit for Applications security and bug fix update
A flaw was found in undertow. The undertow client is not checking the server identity the server certificate presents in HTTPS connections. This is a compulsory step ( that should at least be performed by default) in HTTPS and in http/2.
Migration Toolkit for Applications 6.1.0 ImagesSecurity Fix(es): keycloak: path traversal via double URL encoding (CVE-2022-3782) spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client (CVE-2022-31690) xstream: Denial of Service by injecting recursive collections or maps based on element's hash values raising a stack overflow (CVE-2022-41966) Apache CXF: SSRF Vulnerability (CVE-2022-46364) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Migration Toolkit for Applications 6.0.1 ImagesSecurity Fix(es) from Bugzilla: loader-utils: prototype pollution in function parseQuery in parseQuery.js (CVE-2022-37601) Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing (CVE-2022-42920) gin: Unsanitized input in the default logger in github.com/gin-gonic/gin (CVE-2020-36567) glob-parent: Regular Expression Denial of Service (CVE-2021-35065) express: "qs" prototype poisoning causes the hang of the node process (CVE-2022-24999) loader-utils:Regular expression denial of service (CVE-2022-37603) golang: net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) json5: Prototype Pollution in JSON5 via Parse Method (CVE-2022-46175) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.