VendorsRed Hatmigration_toolkit_for_applicationsall versions
Vulnerabilities

Red Hat Migration Toolkit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-1132
Keycloak: path transversal in redirection validation
Published 2024-04-17 · Analyzed
8.1EPSS 0.016
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2022-4492
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
Published 2023-02-23 · Modified
7.5EPSS 0.006
CVE-2023-6291
Keycloak: redirect_uri validation bypass
Published 2024-01-26 · Modified
7.1EPSS 0.010
CVE-2026-48710
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
Published 2026-05-26 · Analyzed
6.5KEVEPSS 0.071