-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: Red Hat Single Sign-On 7.2.4 security update
Advisory ID:       RHSA-2018:2428-01
Product:           Red Hat Single Sign-On
Advisory URL:      https://access.redhat.com/errata/RHSA-2018:2428
Issue date:        2018-08-15
CVE Names:         CVE-2017-12624 CVE-2018-8039 CVE-2018-10237 
                   CVE-2018-10862 CVE-2018-10912 CVE-2018-1000180 
====================================================================
1. Summary:

A security update is now available for Red Hat Single Sign-On 7.2 from the
Customer Portal.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat Single Sign-On 7.2 is a standalone server, based on the Keycloak
project, that provides authentication and standards-based single sign-on
capabilities for web and mobile applications.

This release of Red Hat Single Sign-On 7.2.4 serves as a replacement for
Red Hat Single Sign-On 7.2.3, and includes bug fixes and enhancements,
which are documented in the Release Notes document linked to in the
References.

Security Fix(es):

* guava: Unbounded memory allocation in AtomicDoubleArray and
CompoundOrdering classes allow remote attackers to cause a denial of
service (CVE-2018-10237)

* bouncycastle: flaw in the low-level interface to RSA key pair generator
(CVE-2018-1000180)

* cxf: Improper size validation in message attachment header for JAX-WS and
JAX-RS services (CVE-2017-12624)

* wildfly: wildfly-core: Path traversal can allow the extraction of .war
archives to write arbitrary files (CVE-2018-10862)

* cxf-core: apache-cxf: TLS hostname verification does not work correctly
with com.sun.net.ssl.* (CVE-2018-8039)

* keycloak: infinite loop in session replacement leading to denial of
service (CVE-2018-10912)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

3. Solution:

Before applying the update, back up your existing installation, including
all applications, configuration files, databases and database settings, and
so on.

The References section of this erratum contains a download link (you must
log in to download the update).

4. Bugs fixed (https://bugzilla.redhat.com/):

1515976 - CVE-2017-12624 cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services
1573391 - CVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service
1588306 - CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator
1593527 - CVE-2018-10862 wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)
1595332 - CVE-2018-8039 apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.*
1607624 - CVE-2018-10912 keycloak: infinite loop in session replacement leading to denial of service

5. JIRA issues fixed (https://issues.redhat.com/):

RHSSO-1429 - CVE-2018-10912 [7.2.z] Replace command might fail and cause endless loop when cache owners >= 2

6. References:

https://access.redhat.com/security/cve/CVE-2017-12624
https://access.redhat.com/security/cve/CVE-2018-8039
https://access.redhat.com/security/cve/CVE-2018-10237
https://access.redhat.com/security/cve/CVE-2018-10862
https://access.redhat.com/security/cve/CVE-2018-10912
https://access.redhat.com/security/cve/CVE-2018-1000180
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=core.service.rhsso&version=7.2
https://access.redhat.com/documentation/en-us/red_hat_single_sign_on/?version=7.2

7. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBW3QOg9zjgjWX9erEAQisnQ//cwFwnyBl0PIh7fW+w9lvxODHbiePYCaL
U07BwYqn/xd0H/5Ddse3fWWNRoG6yho/2sz4yyMK9MZuLIikO5XK+JiXJ1yLQFQf
OPurveJVWA6886/u/cYuqfL/bluigsKkD+FrmFfLOVV57Tx5w2GNgMYTSsWFhBMu
pyQ1ZzV07gTiFq4u2SQTsluRoQ18IoAcjoUuyEXpPOfvH8zrkuYRPCH2qw5mc+hk
JD2XpaZaKDF7cCTmi/zyNcVhIIUM8iKuiBVOiq+jAGwkk8xZkPSnwgFufVoqeiuh
lHpJLVNpcoTyyN+kk+IVi7/t3Rt2DyE9+QkT6N7uwKZLax6fpr4pPZutWzB9y9LP
lGrdGpbJpNNqAaj6CgeNSWV2OEdUQheGtJ9v/OWAEdWKGnA/7RHbO0QDMZqhZnO3
kx9WdFvZVPhVml5aMGKi1mOnBuvPWAeJ1kRqkRWS+yysgq6HkCR4/wof90ZedDTc
KNucOUSwN7arOgws7O9f/kAkH/M8oDmY/77qvAQJTBNMnFPCAtdzurA5gqHGH2pd
PWMn+1HgbgAlKDtT7396YNUBQwhxup2djplyXuYvJgIO1151jQ23yoae9vYcosrk
+0/F6g3LbFy9GfZJczL3nG05YVsQWlbbYC6S1w73+Q+n4AfzaOyTq66i19V64n0x
33uiCNzJkZU=S5zD
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2018-2428:01 Important: Red Hat Single Sign-On 7.2.4 security

A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal

Summary

Red Hat Single Sign-On 7.2 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.
This release of Red Hat Single Sign-On 7.2.4 serves as a replacement for Red Hat Single Sign-On 7.2.3, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.
Security Fix(es):
* guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service (CVE-2018-10237)
* bouncycastle: flaw in the low-level interface to RSA key pair generator (CVE-2018-1000180)
* cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services (CVE-2017-12624)
* wildfly: wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (CVE-2018-10862)
* cxf-core: apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* (CVE-2018-8039)
* keycloak: infinite loop in session replacement leading to denial of service (CVE-2018-10912)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
The References section of this erratum contains a download link (you must log in to download the update).

References

https://access.redhat.com/security/cve/CVE-2017-12624 https://access.redhat.com/security/cve/CVE-2018-8039 https://access.redhat.com/security/cve/CVE-2018-10237 https://access.redhat.com/security/cve/CVE-2018-10862 https://access.redhat.com/security/cve/CVE-2018-10912 https://access.redhat.com/security/cve/CVE-2018-1000180 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=core.service.rhsso&version=7.2 https://access.redhat.com/documentation/en-us/red_hat_single_sign_on/?version=7.2

Package List


Severity
Advisory ID: RHSA-2018:2428-01
Product: Red Hat Single Sign-On
Advisory URL: https://access.redhat.com/errata/RHSA-2018:2428
Issued Date: : 2018-08-15
CVE Names: CVE-2017-12624 CVE-2018-8039 CVE-2018-10237 CVE-2018-10862 CVE-2018-10912 CVE-2018-1000180

Topic

A security update is now available for Red Hat Single Sign-On 7.2 from theCustomer Portal.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

1515976 - CVE-2017-12624 cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services

1573391 - CVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service

1588306 - CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator

1593527 - CVE-2018-10862 wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)

1595332 - CVE-2018-8039 apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.*

1607624 - CVE-2018-10912 keycloak: infinite loop in session replacement leading to denial of service

5. JIRA issues fixed (https://issues.redhat.com/):

RHSSO-1429 - CVE-2018-10912 [7.2.z] Replace command might fail and cause endless loop when cache owners >= 2


Related News