Red Hat Security Advisory: Migration Toolkit for Containers (MTC) 1.8.4 security and bug fix update
🔗 CVE IDs covered (13)
📋 Description
CVE-2019-25211 — github.com/gin-contrib/cors: Gin mishandles a wildcard in the origin string in github.com/gin-contrib/cors CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-45289 — golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-4068 — braces: fails to limit the number of characters it can handle CVE-2024-24788 — golang: net: malformed DNS message can cause infinite loop CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-28849 — follow-redirects: Possible credential leak CVE-2024-28863 — node-tar: denial of service while parsing a tar file due to lack of folders depth validation CVE-2024-29018 — moby: external DNS requests from 'internal' networks could lead to data exfiltration CVE-2024-29041 — express: cause malformed URLs to be evaluated CVE-2024-29180 — webpack-dev-middleware: lack of URL validation may lead to file leak CVE-2024-39338 — axios: axios: Server-Side Request Forgery
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2024:7164
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268018
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269576
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270863
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274767
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2279814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2280600
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2290901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293200
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295302
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2299624
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2299625
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2299628
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2299668
- externalhttps://issues.redhat.com/browse/MIG-1592
- externalhttps://issues.redhat.com/browse/MIG-1593
- externalhttps://issues.redhat.com/browse/MIG-1598
- externalhttps://issues.redhat.com/browse/MIG-1610
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7164.json