-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Migration Toolkit for Runtimes security bug fix and enhancement update Advisory ID: RHSA-2023:1285-01 Product: Migration Toolkit for Runtimes Advisory URL: https://access.redhat.com/errata/RHSA-2023:1285 Issue date: 2023-03-16 CVE Names: CVE-2022-3782 CVE-2022-31690 CVE-2022-46364 ===================================================================== 1. Summary: Migration Toolkit for Runtimes 1.0.2 release Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Migration Toolkit for Runtimes 1.0.2 ZIP artifacts Security Fix(es): * keycloak: path traversal via double URL encoding (CVE-2022-3782) * spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client (CVE-2022-31690) * Apache CXF: SSRF Vulnerability (CVE-2022-46364) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2138971 - CVE-2022-3782 keycloak: path traversal via double URL encoding 2155682 - CVE-2022-46364 Apache CXF: SSRF Vulnerability 2162200 - CVE-2022-31690 spring-security-oauth2-client: Privilege Escalation in spring-security-oauth2-client 5. References: https://access.redhat.com/security/cve/CVE-2022-3782 https://access.redhat.com/security/cve/CVE-2022-31690 https://access.redhat.com/security/cve/CVE-2022-46364 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=migration.toolkit.runtimes&downloadType=distributions 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZBLeC9zjgjWX9erEAQhOgxAAk/jRsjkrCxiJurClPSOMhcoTrWW8klIH 2YdMia9aPsx2g8qkN7VVUflIu5EoQArGMYqicWAfp5FjkTu7zCCk+VTGjJlScxzD 07tv3ZllsNG8HAmQPiUfbwiAcqS6p0TGhCqbR6qusVnhSOW3S7n817IX2dVkPWOM z8/J7UpG0ewJX+DTZ7sFCv6QfJTN5hbKZMks6OsWRl3H4Xo0PCt9S/KK2tXNQTsi kJz06WMN+AcCMYzy7BrdFdbMNpWuY7VHBUeK074Awc+18+LMD4Ed/qiCMoYVxn2K ui2O9ldlLzT6OQerKHdWhcAYHNk/yh7ufFgznte4e0ePDsVEK/7q4NLCzLjFd1S5 n4weYCtg7BUGj4oR0hNEq/2eejarh6PBxP0rGYW/uIPP3Kfge2gz8KNRPIvCDcy0 4C0DrFTxcN3mcYNTawso6EgUDqsJNtOLykwgOjhYb5Re59PU4T+7FFHZW+xPuJMQ bzBk2u0Z0PUKyh8UTPCdoLC06I6tpUGkKKwMEVO0VVg7l0QP8m/oHj35gnIgKrVl vMzJNkRBK48pU57E6Ps1rDOA7/JiNwieuD2QoJuQRGo+Z98L3VZzSIUvtyjy4+Rj 4y1H1ttN02I3lwbPCtEBE2qu6R24karIVJtyLV1x4QsfLnyINiFm4upf2eEInVU3 w4QAo3uuIhA= =pwgJ -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce