이 콘텐츠는 선택한 언어로 제공되지 않습니다.

Chapter 6. MTA 6.1.0


6.1. New features and improvements

This section describes the new features and improvements of the Migration Toolkit for Applications (MTA) 6.1.0.

Creating custom migration targets

Administrators and architects can create and maintain custom migration targets and populate them with custom rules from a repository. Such custom migration targets are available for use by non-admin users. This simplifies the process of analysis configuration for applications with similar technologies that are common across the entire application portfolio of an organization.

Automated tagging of resources

MTA uses the technology stack information that the analysis module collects during an analysis to generate tags and to attach them automatically to applications.

Downloading HTML and CSV analysis reports

Users can download HTML and CSV reports generated by application analysis. By default, this option is disabled; it can be enabled in the new General menu in Administration view.

Reviewing an application without an assessment

Architects can review applications without running assessments first. By default, this option is disabled; it can be enabled in the new General menu in Administration view.

Support for disconnected installation

MTA fully supports disconnected installation in air-gapped OpenShift Container Platform environments.

Changes in naming

Some entities and menu entries of the MTA user interface have been renamed for clarity. The Administrator and Developer views have been renamed to Administration and Migration, respectively. Tag Types are now named Tag Categories.

6.2. Known issues

In this release, the following known issues have been identified.

CVE-2023-44487 HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

A flaw was found in the handling of multiplexed streams in the HTTP/2 protocol, which is utilized by Migration Toolkit for Applications (MTA). A client could repeatedly make a request for a new multiplex stream then immediately send an RST_STREAM frame to cancel those requests. This activity created additional workloads for the server in terms of setting up and dismantling streams, but avoided any server-side limitations on the maximum number of active streams per connection. As a result, a denial of service occurred due to server resource consumption.

The following issues have been listed under this issue:

To resolve this issue, upgrade to MTA 6.1.4.

For more details, see CVE-2023-44487 (Rapid Reset Attack)

CVE-2023-39325: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack in the Go language packages)

The HTTP/2 protocol is susceptible to a denial of service attack because request cancellation can reset multiple streams quickly. The server has to set up and tear down the streams while not hitting any server-side limit for the maximum number of active streams per connection. This results in a denial of service due to server resource consumption.

The following issues have been listed under this issue:

To resolve this issue, upgrade to MTA 6.1.4.

For more information, see CVE-2023-39325 (Rapid Reset Attack in the Go language packages).

Application analysis fails if the name of custom rules directory has spaces

During the configuration of an application analysis, if the user fetches custom rules from a repository using the CLI and the root path contains spaces, the CLI command is not properly composed and the analysis fails. The user must make sure that there are no spaces in the name of the directory from which custom rules are taken.

6.3. Resolved issues

For a complete list of all issues resolved in this release, see the list of MTA 6.1.0 resolved issues in Jira.

맨 위로 이동
Red Hat logoGithubredditYoutubeTwitter

자세한 정보

평가판, 구매 및 판매

커뮤니티

Red Hat 문서 정보

Red Hat을 사용하는 고객은 신뢰할 수 있는 콘텐츠가 포함된 제품과 서비스를 통해 혁신하고 목표를 달성할 수 있습니다. 최신 업데이트를 확인하세요.

보다 포괄적 수용을 위한 오픈 소스 용어 교체

Red Hat은 코드, 문서, 웹 속성에서 문제가 있는 언어를 교체하기 위해 최선을 다하고 있습니다. 자세한 내용은 다음을 참조하세요.Red Hat 블로그.

Red Hat 소개

Red Hat은 기업이 핵심 데이터 센터에서 네트워크 에지에 이르기까지 플랫폼과 환경 전반에서 더 쉽게 작업할 수 있도록 강화된 솔루션을 제공합니다.

Theme

© 2025 Red Hat