Migration Toolkit for Runtimes 1.2.7 ZIP artifactsSecurity Fix(es): netty-codec-http: Allocation of Resources Without Limits or Throttling (CVE-2024-29025) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Migration Toolkit for Runtimes 1.2.7 ImagesSecurity Fix(es): org.jsoup/jsoup: The jsoup cleaner may incorrectly sanitize crafted XSS attempts if SafeList.preserveRelativeLinks is enabled (CVE-2022-36033) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: Migration Toolkit for Runtimes security, bug fix and enhancement update
Important: Migration Toolkit for Runtimes security, bug fix and enhancement update
Migration Toolkit for Runtimes 1.2.5 Images<br>Security Fix(es):<br><li> vertx-core: memory leak when a TCP server is configured with TLS and SNI support (CVE-2024-1300)</li> <li> commons-compress: OutOfMemoryError unpacking broken Pack200 file (CVE-2024-26308)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s)<br>listed in the References section.
Migration Toolkit for Runtimes 1.2.5 ZIP artifactsSecurity Fix(es): commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file (CVE-2024-25710) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Migration Toolkit for Runtimes 1.2.4 ImagesSecurity Fix(es): nodejs-semver: Regular expression denial of service (CVE-2022-25883) jackson-databind: denial of service via cylic dependencies (CVE-2023-35116) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Migration Toolkit for Runtimes 1.2.3 ImagesSecurity Fix(es): jettison: Uncontrolled Recursion in JSONArray (CVE-2023-1436) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: Migration Toolkit for Runtimes security update
Important: Migration Toolkit for Runtimes security update
Important: Migration Toolkit for Runtimes security update
Migration Toolkit for Runtimes 1.1.1 ImagesSecurity Fix(es): undertow: Server identity in https connection is not checked by the undertow client (CVE-2022-4492) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
A flaw was found in undertow. The undertow client is not checking the server identity the server certificate presents in HTTPS connections. This is a compulsory step ( that should at least be performed by default) in HTTPS and in http/2.
Moderate: Migration Toolkit for Runtimes security update