Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:6656 - Security Advisory
Issued:
2024-09-12
Updated:
2024-09-12

RHSA-2024:6656 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Migration Toolkit for Runtimes security, bug fix and enhancement update

Type/Severity

Security Advisory: Moderate

Topic

Migration Toolkit for Runtimes 1.2.7 release
Red Hat Product Security has rated this update as having a security impact of Moderate.
A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Migration Toolkit for Runtimes 1.2.7 Images

Security Fix(es):

  • org.jsoup/jsoup: The jsoup cleaner may incorrectly sanitize crafted XSS attempts if SafeList.preserveRelativeLinks is enabled (CVE-2022-36033)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Install the latest version of the Migration Toolkit for Runtimes from the Red Hat catalog in the OperatorHub page within your OpenShift instance.

Affected Products

  • Red Hat Migration Toolkit for Runtimes Advisory Metadata x86_64

Fixes

  • WINDUPRULE-1050 - JBoss EAP 6.4 broken links to documentation

CVEs

  • CVE-2022-36033
  • CVE-2023-2953
  • CVE-2024-2398
  • CVE-2024-6345
  • CVE-2024-21131
  • CVE-2024-21138
  • CVE-2024-21140
  • CVE-2024-21144
  • CVE-2024-21145
  • CVE-2024-21147
  • CVE-2024-25062
  • CVE-2024-28182
  • CVE-2024-35235
  • CVE-2024-37370
  • CVE-2024-37371

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

mtr/mtr-operator-bundle@sha256:75ebbef1804fbcb83ee23b2e65ea2a70612ecc6d4db5185274944c9651cedbfd
mtr/mtr-rhel8-operator@sha256:1ea56096b9b1101e226f1f9bf08a04f7c9a34e926004ad385db47c0ea6de1e73
mtr/mtr-web-executor-container-rhel8@sha256:607c54e52652334be36ef3b10745df01c42dc9f95787ca3e9e472a10d3982cf3

ppc64le

mtr/mtr-operator-bundle@sha256:d21a3b40cd89103a1d280ea8d91f17b55d0ab31c340510989c296d9d6b207a63
mtr/mtr-rhel8-operator@sha256:6d9f1cd11c62b093d0998ada19d570d2dc2aa81548e6bacb9b1a141d58d53c0c
mtr/mtr-web-container-rhel8@sha256:0a0662d4d8215057624af15121f03206d13665df318ca1075a5fe605b49d8ead
mtr/mtr-web-executor-container-rhel8@sha256:61cc20767de585645674ba9754872e2a8195a17d2a2406c2465621fcf9750bda

s390x

mtr/mtr-operator-bundle@sha256:d3049bd81b789e1e6139f65482f2a561e2f3951ff23a2053fe3aea1c920171c1
mtr/mtr-rhel8-operator@sha256:dffa2b0c8da17f275ddbb7c93d298fa863e223c9135838b5cf305ae09a1b99c1
mtr/mtr-web-container-rhel8@sha256:0fba106644240713f8ebbad92089b4e63a8030ecb4671ab12cd21cdd47d10459
mtr/mtr-web-executor-container-rhel8@sha256:a7e78424a9f361181f5d07f17ace0659be0d2f1156cf3457836a94a116e75839

x86_64

mtr/mtr-operator-bundle@sha256:190a6fa2a6a9b6b182cdf9cab18814d05c203b54ca18dc533e553fa5dcca779e
mtr/mtr-rhel8-operator@sha256:7d50eab932d763330b1ce37d36842598f110884c1af798e1f2f5629c5d223e52
mtr/mtr-web-container-rhel8@sha256:487d22a14ff07e7fb2c1c16e054481bbd5e59b3de9dabb871c75885f7b9e3801
mtr/mtr-web-executor-container-rhel8@sha256:df22ed74f2ef56af2192da45fa02e1e4ab76e2106b4b42740a1160df06b9d259

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility