-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: RH-SSO 7.4.1 adapters for Red Hat JBoss Enterprise Application Platform 7
Advisory ID:       RHSA-2020:2814-01
Product:           Red Hat JBoss Enterprise Application Platform
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2814
Issue date:        2020-07-02
CVE Names:         CVE-2020-1714 
====================================================================
1. Summary:

A security update is now available for Red Hat Single Sign-On 7.4.1
adapters for Red Hat JBoss Enterprise Application Platform 7.3

Red Hat Product Security has rated this update as having a security impact
of
Important. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat JBoss EAP 7.3 for BaseOS-8 - noarch
Red Hat JBoss EAP 7.3 for RHEL 6 Server - noarch
Red Hat JBoss EAP 7.3 for RHEL 7 Server - noarch

3. Description:

Packages: Red Hat Single Sign-On 7.4.1 adapters for Red Hat JBoss
Enterprise Application Platform 7.3

Security Fix(es):

* keycloak: Lack of checks in ObjectInputStream leading to Remote Code
Execution (CVE-2020-1714)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s)
listed in the References section.

4. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1705975 - CVE-2020-1714 keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution

6. JIRA issues fixed (https://issues.redhat.com/):

KEYCLOAK-13957 - Create RPMs for the RH-SSO 7.4.1 adapters for EAP7

7. Package List:

Red Hat JBoss EAP 7.3 for RHEL 6 Server:

Source:
eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el6eap.src.rpm

noarch:
eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el6eap.noarch.rpm
eap7-keycloak-saml-adapter-sso7_4-9.0.4-1.redhat_00001.1.el6eap.noarch.rpm

Red Hat JBoss EAP 7.3 for RHEL 7 Server:

Source:
eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el7eap.src.rpm

noarch:
eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el7eap.noarch.rpm
eap7-keycloak-saml-adapter-sso7_4-9.0.4-1.redhat_00001.1.el7eap.noarch.rpm

Red Hat JBoss EAP 7.3 for BaseOS-8:

Source:
eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el8eap.src.rpm

noarch:
eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el8eap.noarch.rpm
eap7-keycloak-saml-adapter-sso7_4-9.0.4-1.redhat_00001.1.el8eap.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

8. References:

https://access.redhat.com/security/cve/CVE-2020-1714
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/documentation/en-us/red_hat_single_sign-on/7.4/

9. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXv3jhtzjgjWX9erEAQgbRQ//ZudbG/tllELWesMM/duq65/Lhe6ytRhc
G9G4EE2rBM/ZcM4kWyUAi5P48hrZR8BjDRNB09fRxyxTu4qBPx3lCbz4Mw1ndObj
fZZ6EAOJKTJHpsgNP31hkhmkZ3KuHkvPlIAZSp6/ebEr266vyDXGJXQ7+XNZWKpq
d/o+ztHr2kXu9fhc6FnMPNBIGtE9IhY7Xnho7zNCyQX0WJ5J1sFoTGy03UmcRr4n
bUHl37qfJyydW1DwZjt3Qs94Hn8pBKSDv0XppLklOghzC8hK8usTZvqu5PkxzvUF
1VYZ1YwN7t5Q9xwxG3uGIROJRPzCVxPEIIqyhfesQLWU8fDHhoAWyFN5nHxsLaJG
rLqecNNLSzwRPmfu12PtaCJvZvsDokeErsrW88DsnuB0UOVBNY1080zvj/8Ozvdm
4WZYxL1tyahcczTj7IEMBstYIxxOgKje6/lXhhG6MEYedfER+AGSGtnuXChB2SEw
RTKxBG9mavLjazCmAx00tzeMKAT4M7VSfB70GLoliOsHkFpFbeFrYiz/Tni/uN3q
kTRUKOasfKRngBNhR1/Af69s2idS9T32kRgfTYRLVhlivuE0FQ5EzI/IyQN8FXME
2+9fEjj92jRLa7t2yrnvrb318mlbXKlmLAkLZygjsSIqMDrH5zC7CJsun62J3GOK
LFWKe3OCrMw=1EL6
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-2814:01 Important: RH-SSO 7.4.1 adapters for Red Hat

A security update is now available for Red Hat Single Sign-On 7.4.1 adapters for Red Hat JBoss Enterprise Application Platform 7.3 Red Hat Product Security has rated this update as...

Summary

Packages: Red Hat Single Sign-On 7.4.1 adapters for Red Hat JBoss Enterprise Application Platform 7.3
Security Fix(es):
* keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution (CVE-2020-1714)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-1714 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/documentation/en-us/red_hat_single_sign-on/7.4/

Package List

Red Hat JBoss EAP 7.3 for RHEL 6 Server:
Source: eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el6eap.src.rpm
noarch: eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el6eap.noarch.rpm eap7-keycloak-saml-adapter-sso7_4-9.0.4-1.redhat_00001.1.el6eap.noarch.rpm
Red Hat JBoss EAP 7.3 for RHEL 7 Server:
Source: eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el7eap.src.rpm
noarch: eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el7eap.noarch.rpm eap7-keycloak-saml-adapter-sso7_4-9.0.4-1.redhat_00001.1.el7eap.noarch.rpm
Red Hat JBoss EAP 7.3 for BaseOS-8:
Source: eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el8eap.src.rpm
noarch: eap7-keycloak-adapter-sso7_4-9.0.4-1.redhat_00001.1.el8eap.noarch.rpm eap7-keycloak-saml-adapter-sso7_4-9.0.4-1.redhat_00001.1.el8eap.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2020:2814-01
Product: Red Hat JBoss Enterprise Application Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2020:2814
Issued Date: : 2020-07-02
CVE Names: CVE-2020-1714

Topic

A security update is now available for Red Hat Single Sign-On 7.4.1adapters for Red Hat JBoss Enterprise Application Platform 7.3Red Hat Product Security has rated this update as having a security impactofImportant. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat JBoss EAP 7.3 for BaseOS-8 - noarch

Red Hat JBoss EAP 7.3 for RHEL 6 Server - noarch

Red Hat JBoss EAP 7.3 for RHEL 7 Server - noarch


Bugs Fixed

1705975 - CVE-2020-1714 keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution

6. JIRA issues fixed (https://issues.redhat.com/):

KEYCLOAK-13957 - Create RPMs for the RH-SSO 7.4.1 adapters for EAP7


Related News