-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Migration Toolkit for Runtimes security update Advisory ID: RHSA-2023:3813-01 Product: Migration Toolkit for Runtimes Advisory URL: https://access.redhat.com/errata/RHSA-2023:3813 Issue date: 2023-06-27 CVE Names: CVE-2021-3782 CVE-2022-3627 CVE-2022-3970 CVE-2022-4492 CVE-2022-36227 CVE-2023-0361 CVE-2023-2491 CVE-2023-27535 ===================================================================== 1. Summary: An update for mtr-operator-bundle-container, mtr-operator-container, mtr-web-container, and mtr-web-executor-container is now available for Migration Toolkit for Runtimes 1 on RHEL 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Migration Toolkit for Runtimes 1.1.1 Images Security Fix(es): * undertow: Server identity in https connection is not checked by the undertow client (CVE-2022-4492) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2153260 - CVE-2022-4492 undertow: Server identity in https connection is not checked by the undertow client 5. References: https://access.redhat.com/security/cve/CVE-2021-3782 https://access.redhat.com/security/cve/CVE-2022-3627 https://access.redhat.com/security/cve/CVE-2022-3970 https://access.redhat.com/security/cve/CVE-2022-4492 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-2491 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/updates/classification/#moderate 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZJsFrNzjgjWX9erEAQjqvBAAgwT2yGcVY1aE8h9lrW8X4Dmb4Yq65hVm 0Qk6n0BjmDT5kne1VBWwJPyE+oAiLVDmnBI1quqARSmMVZoQVQpcNImwLF0A5pU9 8xfSvVnaKp7x3fEoxE5gXUQd9z4N7osKtZLg0xvTeHo2ip4BxSpKvyu8TDjorPUk YXOkMxi1YZX180suGio4Rtp5GNwOVNdpvLu4o+/XUKzREHVAI6VbB5DI12Joy5I0 BeQkEkxAWQ6tIh9WIr0QSK82T0f1xsQFNG/tzrNbtRKbcOyiiiv15MINrLFufmLY hbxslHSxsFdur8GC6VbsPfMdPDMI3MgMnSYH+2GTz7zalVAIntbfwoWfaJ7b5ZWw bP/oohbKuTzGCcWZn2PpqjAPajS00DJTWL8q9EH44PGUv48qS2sDjFyWp6xtNyCp ceDOD56qFECZ6hO9STUwJ4pyJPVRI+2+OVzgMaqkQPHAfo6tKv6DJ9BXuWuGdf7g 5lKDHRhLT8sDNHU91rbjYT31sqiE14jHkseZ8jSExMFJGtwN9gVJmCRxwjPzJuJV 4hPh5otnYfHeq7jZ4Ra/aUDzeBxVl6w1j3CCGtEaypyZ51hTu5QRzsZ1KyIPQH09 mrX2H+a9uSkLU+KGyNe1fwKmIVAQca9s+C5SLdmgEFRwAMntCBF5oRSm30xlas9T Clr44cObnDs= =Yq4r -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce