An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting confidentiality, integrity, and availability of the services located on that cluster.
The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API.Security Fix(es): nodejs-url-parse: authorization bypass through user-controlled key (CVE-2022-0512) npm-url-parse: Authorization bypass through user-controlled key (CVE-2022-0686) npm-url-parse: authorization bypass through user-controlled key (CVE-2022-0691) eventsource: Exposure of Sensitive Information (CVE-2022-1650) nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions (CVE-2020-28500) nodejs-lodash: command injection via template (CVE-2021-23337) npm-url-parse: Authorization Bypass Through User-Controlled Key (CVE-2022-0639) golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API.Security Fix(es): nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807) golang: archive/zip: malformed archive may cause panic or memory exhaustion (incomplete fix of CVE-2021-33196) (CVE-2021-39293) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API.Security Fix(es): golang: net/http/httputil: panic due to racy read of persistConn after handler panic (CVE-2021-36221) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API.Security Fix(es): mig-controller: incorrect namespaces handling may lead to not authorized usage of Migration Toolkit for Containers (MTC) (CVE-2021-3948) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
The Migration Toolkit for Containers (MTC) enables you to migrateKubernetes resources, persistent volume data, and internal container imagesbetween OpenShift Container Platform clusters, using the MTC web console orthe Kubernetes API.Security Fix(es): nodejs-immer: prototype pollution may lead to DoS or remote code execution (CVE-2021-3757) mig-controller: incorrect namespaces handling may lead to not authorized usage of Migration Toolkit for Containers (MTC) (CVE-2021-3948) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.
The Migration Toolkit for Containers (MTC) enables you to migrateKubernetes resources, persistent volume data, and internal container imagesbetween OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API.Security fixes: golang: net: lookup functions may return invalid host names (CVE-2021-33195) golang: archive/zip: malformed archive may cause panic or memory exhaustion (CVE-2021-33196) golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty (CVE-2021-33197) golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents (CVE-2021-33198) golang: crypto/tls: certificate of wrong type is causing TLS client to panic (CVE-2021-34558) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.