RHSA-2023:3813: Moderate: Migration Toolkit for Runtimes security update
Migration Toolkit for Runtimes 1.1.1 ImagesSecurity Fix(es): undertow: Server identity in https connection is not checked by the undertow client (CVE-2022-4492) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3813?
The severity of RHSA-2023:3813 is classified as moderate.
What vulnerability is addressed in RHSA-2023:3813?
RHSA-2023:3813 addresses a vulnerability where the server identity in HTTPS connections is not checked by the Undertow client (CVE-2022-4492).
How do I fix RHSA-2023:3813?
To fix RHSA-2023:3813, update to the latest version of Migration Toolkit for Runtimes as per Red Hat's guidance.
What impact does CVE-2022-4492 have in RHSA-2023:3813?
CVE-2022-4492 can lead to security risks as the client does not validate the server's identity in HTTPS connections.
Is it safe to use versions affected by RHSA-2023:3813?
Using affected versions poses a risk due to the vulnerability, and it is recommended to apply the security fix as soon as possible.