Red Hat 9036 Published by

A Migration Toolkit for Containers (MTC) 1.8.0 security and bug fix update has been released.



[RHSA-2023:5447-01] Important: Migration Toolkit for Containers (MTC) 1.8.0 security and bug fix update


====================================================================
Red Hat Security Advisory

Synopsis: Important: Migration Toolkit for Containers (MTC) 1.8.0 security and bug fix update
Advisory ID: RHSA-2023:5447-01
Product: Red Hat Migration Toolkit
Advisory URL: https://access.redhat.com/errata/RHSA-2023:5447
Issue date: 2023-10-05
CVE Names: CVE-2023-0800 CVE-2023-0801 CVE-2023-0802
CVE-2023-0803 CVE-2023-0804 CVE-2023-2602
CVE-2023-2603 CVE-2023-3899 CVE-2023-4863
CVE-2023-5129 CVE-2023-26115 CVE-2023-27536
CVE-2023-28321 CVE-2023-28484 CVE-2023-29469
CVE-2023-29491 CVE-2023-30630 CVE-2023-32681
====================================================================
1. Summary:

The Migration Toolkit for Containers (MTC) 1.8.0 is now available.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

The Migration Toolkit for Containers (MTC) enables you to migrate
Kubernetes resources, persistent volume data, and internal container images
between OpenShift Container Platform clusters, using the MTC web console or
the Kubernetes API.

Security Fix(es):

* word-wrap: ReDoS (CVE-2023-26115)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Bug Fix(es):

* MTC version is not displayed correctly in the UI (BZ#2233026)

* Indirect migration is stuck on backup stage (BZ#2233097)

* Migrated application unable to pull image from internal registry on
target cluster (BZ#2233103)

* PodVolumeRestore remain In Progress keeping the migration stuck at Stage
Restore (BZ#2233868)

* Migration failing on Azure due to authorization issue (BZ#2238974)

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed ( https://bugzilla.redhat.com/):

2216827 - CVE-2023-26115 word-wrap: ReDoS
2233026 - MTC version is not displayed correctly in the UI
2233097 - Indirect migration is stuck on backup stage
2233103 - Migrated application unable to pull image from internal registry on target cluster
2233868 - PodVolumeRestore remain In Progress keeping the migration stuck at Stage Restore
2238974 - Migration failing on Azure due to authorization issue

5. JIRA issues fixed ( https://issues.redhat.com/):

MIG-1331 - MTC generates continued requests to Azure Storage API
MIG-1363 - Upgrade OADP dependency to latest version
MIG-1411 - mtc-operator specification is missing related image registry.redhat.io/rhmtc/openshift-migration-must-gather-rhel8

6. References:

https://access.redhat.com/security/cve/CVE-2023-0800
https://access.redhat.com/security/cve/CVE-2023-0801
https://access.redhat.com/security/cve/CVE-2023-0802
https://access.redhat.com/security/cve/CVE-2023-0803
https://access.redhat.com/security/cve/CVE-2023-0804
https://access.redhat.com/security/cve/CVE-2023-2602
https://access.redhat.com/security/cve/CVE-2023-2603
https://access.redhat.com/security/cve/CVE-2023-3899
https://access.redhat.com/security/cve/CVE-2023-4863
https://access.redhat.com/security/cve/CVE-2023-5129
https://access.redhat.com/security/cve/CVE-2023-26115
https://access.redhat.com/security/cve/CVE-2023-27536
https://access.redhat.com/security/cve/CVE-2023-28321
https://access.redhat.com/security/cve/CVE-2023-28484
https://access.redhat.com/security/cve/CVE-2023-29469
https://access.redhat.com/security/cve/CVE-2023-29491
https://access.redhat.com/security/cve/CVE-2023-30630
https://access.redhat.com/security/cve/CVE-2023-32681
https://access.redhat.com/security/updates/classification/#important

7. Contact:

The Red Hat security contact is [secalert@redhat.com]. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.

--