rhsa-2024_6487
Vulnerability from csaf_redhat
Published
2024-09-09 10:39
Modified
2024-12-27 14:19
Summary
Red Hat Security Advisory: MTV 2.6.6 Images

Notes

Topic
Updated Release packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Details
Migration Toolkit for Virtualization 2.6.6 Images Security Fix(es): * Empty bearer token may perform authentication (CVE-2024-8509) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Terms of Use
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.



{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "Updated Release packages that fix several bugs and add various enhancements are now available.\n\nRed Hat Product Security has rated this update as having a security impact\nof Important. A Common Vulnerability Scoring System (CVSS) base score, which\ngives a detailed severity rating, is available for each vulnerability from\nthe CVE link(s) in the References section.",
        "title": "Topic"
      },
      {
        "category": "general",
        "text": "Migration Toolkit for Virtualization 2.6.6 Images\n\nSecurity Fix(es):\n\n* Empty bearer token may perform authentication (CVE-2024-8509)\n\nFor more details about the security issue(s), including the impact, a CVSS\nscore, acknowledgments, and other related information, refer to the CVE\npage(s) listed in the References section.",
        "title": "Details"
      },
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://access.redhat.com/errata/RHSA-2024:6487",
        "url": "https://access.redhat.com/errata/RHSA-2024:6487"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/updates/classification/#important",
        "url": "https://access.redhat.com/security/updates/classification/#important"
      },
      {
        "category": "external",
        "summary": "2310406",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310406"
      },
      {
        "category": "external",
        "summary": "MTV-1353",
        "url": "https://issues.redhat.com/browse/MTV-1353"
      },
      {
        "category": "external",
        "summary": "MTV-1354",
        "url": "https://issues.redhat.com/browse/MTV-1354"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6487.json"
      }
    ],
    "title": "Red Hat Security Advisory: MTV 2.6.6 Images",
    "tracking": {
      "current_release_date": "2024-12-27T14:19:24+00:00",
      "generator": {
        "date": "2024-12-27T14:19:24+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "4.2.4"
        }
      },
      "id": "RHSA-2024:6487",
      "initial_release_date": "2024-09-09T10:39:29+00:00",
      "revision_history": [
        {
          "date": "2024-09-09T10:39:29+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2024-09-09T10:39:29+00:00",
          "number": "2",
          "summary": "Last updated version"
        },
        {
          "date": "2024-12-27T14:19:24+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "8Base-MTV-2.6",
                "product": {
                  "name": "8Base-MTV-2.6",
                  "product_id": "9Base-MTV-2.6",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2.6::el9"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "8Base-MTV-2.6",
                "product": {
                  "name": "8Base-MTV-2.6",
                  "product_id": "8Base-MTV-2.6",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2.6::el8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Migration Toolkit for Virtualization"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-api-rhel9\u0026tag=2.6.6-2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-console-plugin-rhel9\u0026tag=2.6.6-3"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-controller-rhel9\u0026tag=2.6.6-2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-must-gather-rhel8\u0026tag=2.6.6-1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-openstack-populator-rhel9\u0026tag=2.6.6-2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-operator-bundle\u0026tag=2.6.6-6"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-rhel8-operator\u0026tag=2.6.6-1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-ova-provider-server-rhel9\u0026tag=2.6.6-2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-populator-controller-rhel9\u0026tag=2.6.6-2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-rhv-populator-rhel8\u0026tag=2.6.6-1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-validation-rhel9\u0026tag=2.6.6-2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-virt-v2v-rhel9\u0026tag=2.6.6-2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23_amd64",
                "product": {
                  "name": "migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23_amd64",
                  "product_id": "migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23?arch=amd64\u0026repository_url=registry.redhat.io/migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8\u0026tag=2.6.6-1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9_amd64",
        "relates_to_product_reference": "8Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703_amd64",
        "relates_to_product_reference": "8Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8_amd64",
        "relates_to_product_reference": "8Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23_amd64",
        "relates_to_product_reference": "8Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373_amd64",
        "relates_to_product_reference": "9Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487_amd64",
        "relates_to_product_reference": "9Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8_amd64",
        "relates_to_product_reference": "9Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c_amd64",
        "relates_to_product_reference": "9Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04_amd64",
        "relates_to_product_reference": "9Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a_amd64",
        "relates_to_product_reference": "9Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b_amd64",
        "relates_to_product_reference": "9Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5_amd64",
        "relates_to_product_reference": "9Base-MTV-2.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf_amd64 as a component of 8Base-MTV-2.6",
          "product_id": "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf_amd64"
        },
        "product_reference": "migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf_amd64",
        "relates_to_product_reference": "9Base-MTV-2.6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Andrew Block"
          ],
          "organization": "Red Hat",
          "summary": "This issue was discovered by Red Hat."
        }
      ],
      "cve": "CVE-2024-8509",
      "cwe": {
        "id": "CWE-285",
        "name": "Improper Authorization"
      },
      "discovery_date": "2024-09-06T12:47:14.382000+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9_amd64",
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703_amd64",
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8_amd64",
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf_amd64"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2310406"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability was found in Forklift Controller.\u00a0 There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization header and some form of a Bearer token, a 401 error occurs. The presence of a token value provides a 200 response with the requested information.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "Migration Toolkit for Virtualization: forklift-controller: Empty bearer token may perform authentication",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This vulnerability represents a important severity issue due to its direct impact on the API\u0027s authentication and authorization mechanisms. By failing to properly validate the Bearer token in the Authorization header, the API inadvertently allows unauthorized users to access protected resources, leading to potential data breaches and unauthorized operations. The absence of token verification bypasses the core security controls designed to restrict access, thereby exposing sensitive data and system functionalities to malicious actors.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373_amd64"
        ],
        "known_not_affected": [
          "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9_amd64",
          "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703_amd64",
          "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8_amd64",
          "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23_amd64",
          "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487_amd64",
          "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8_amd64",
          "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c_amd64",
          "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04_amd64",
          "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a_amd64",
          "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b_amd64",
          "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5_amd64",
          "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf_amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2024-8509"
        },
        {
          "category": "external",
          "summary": "RHBZ#2310406",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310406"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2024-8509",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-8509"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2024-8509",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8509"
        }
      ],
      "release_date": "2024-09-06T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2024-09-09T10:39:29+00:00",
          "details": "Before applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\n        https://access.redhat.com/articles/11258",
          "product_ids": [
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373_amd64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2024:6487"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
          "product_ids": [
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9_amd64",
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703_amd64",
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8_amd64",
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf_amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-must-gather-rhel8@sha256:7dcfaca922b348d8365916b0f13d9b3ccd08b1f22d5ac8b8da8ceec9c5bfbdc9_amd64",
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-rhel8-operator@sha256:0512f432ca9acd8b3d0b7e30cb45d4a6cd579ed17be7abd4d5133355a331c703_amd64",
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-rhv-populator-rhel8@sha256:529fb951862ee47d1610d0311bb1f09f789cd5143ea15e02359b425fca94a9a8_amd64",
            "8Base-MTV-2.6:migration-toolkit-virtualization/mtv-virt-v2v-warm-rhel8@sha256:e71ac315ec8335dade9e4ca7a423053066c21495b1db8710d178d39af9316f23_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-api-rhel9@sha256:cda740cdef9b4a9b9499204aa231892bb9cde94b983eed889eb31540bbec4373_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:c2cb73fb7cd7a724e1b17038068065f10a9164b60236c54e1c543ed0a797d487_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-controller-rhel9@sha256:fa371a3bd0fa60171d2485e6f62b66d147f88ebee0cb4c661157f90414c591c8_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-openstack-populator-rhel9@sha256:6ceb75952b4e4044bf56e3d4419bee9a250163290fe78cc7241c6a429b350c7c_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-operator-bundle@sha256:4670638d8471f4e3dfc28159a91b408ad197505ef706b99f8f81054ad2fd3c04_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-ova-provider-server-rhel9@sha256:741cc31bfd2c56fdc04629e4edfd962198ebac47d90062c9fef4efd41d4dc31a_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-populator-controller-rhel9@sha256:927034ecda9089f1bab5ad02905ea4c551a23d3817f2ae7cf69dbeb1a2bf459b_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-validation-rhel9@sha256:209b681a0c380e63dfca572fb622e10e339c8f7178487c9f9d6176e77fdd74a5_amd64",
            "9Base-MTV-2.6:migration-toolkit-virtualization/mtv-virt-v2v-rhel9@sha256:7502871e7c68c95d584321f3280cf7a370b5c597f580dfd3083b486ca8eb42bf_amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "Migration Toolkit for Virtualization: forklift-controller: Empty bearer token may perform authentication"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading...

Loading...

Loading...
  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.