Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Red Hat 7.6.4 Important: Single Sign-On Security Fix Update

red hat
Calendar Grey June 27, 2023
Dist Redhat Esm H88
Critical notice regarding the security revision for Red Hat Single Sign-On 7.6.4 deployed on OpenShift, including recent patches.
A new image is available for Red Hat Single Sign-On 7.6.4, running on OpenShift Container Platform 3.10 and 3.11, and 4.12.0

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat Single Sign-On is an integrated sign-on solution, available as a Red Hat JBoss Middleware for OpenShift containerized image. The Red Hat Single Sign-On for OpenShift image provides an authentication server that you can use to log in centrally, log out, and register. You can also manage user accounts for web applications, mobile applications, and RESTful web services.
This erratum releases a new image for Red Hat Single Sign-On 7.6.4 for use within the OpenShift Container Platform 3.10, OpenShift Container Platform 3.11, and within the OpenShift Container Platform 4.12 cloud computing Platform-as-a-Service (PaaS) for on-premise or private cloud deployments, aligning with the standalone product release.
Security Fix(es):
* keycloak: Cross-site scripting when validating URI-schemes on SAML and OIDC (CVE-2022-4361)
* undertow: Infinite loop in SslConduit during close (CVE-2023-1108)
* keycloak: oauth client impersonation (CVE-2023-2422)
* keycloak: Untrusted Certificate Validation (CVE-2023-1664)
* keycloak: client access via device auth request spoof (CVE-2023-2585)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2022-4361 https://access.redhat.com/security/cve/CVE-2023-1108 https://access.redhat.com/security/cve/CVE-2023-1664 https://access.redhat.com/security/cve/CVE-2023-2422 https://access.redhat.com/security/cve/CVE-2023-2585 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/updates/classification/#important

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2023:3888-01
Product: Red Hat OpenShift Enterprise
Issue date: 2023-06-27

Topic

A new image is available for Red Hat Single Sign-On 7.6.4, running onOpenShift Container Platform 3.10 and 3.11, and 4.12.0.Red Hat Product Security has rated this update as having a security impactofImportant. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2151618 - CVE-2022-4361 Keycloak | RHSSO: XSS due to lax URI scheme validation

2174246 - CVE-2023-1108 Undertow: Infinite loop in SslConduit during close

2182196 - CVE-2023-1664 keycloak: Untrusted Certificate Validation

2191668 - CVE-2023-2422 keycloak: oauth client impersonation

2196335 - CVE-2023-2585 keycloak: client access via device auth request spoof

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here