Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Red Hat Single Sign-On 7.6.4: RHSA-2023:3892-01 Important Security Update

red hat
Calendar Grey June 27, 2023
Dist Redhat Esm H88
Keep up to date with essential news regarding security in Red Hat Single Sign-On 7.6.4. Critical information found within the advisory.
A security update is now available for Red Hat Single Sign-On 7.6 from the Customer Portal

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.
This release of Red Hat Single Sign-On 7.6.4 serves as a replacement for Red Hat Single Sign-On 7.6.3, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.
Security Fix(es):
* keycloak: Cross-site scripting when validating URI-schemes on SAML and OIDC (CVE-2022-4361)
* keycloak: oauth client impersonation (CVE-2023-2422)
* keycloak: Untrusted Certificate Validation (CVE-2023-1664)
* undertow: Infinite loop in SslConduit during close (CVE-2023-1108)
* keycloak: client access via device auth request spoof (CVE-2023-2585)
* xstream: Arbitrary code execution via unsafe deserialization of sun.tracing.* (CVE-2021-39144)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2021-39144 https://access.redhat.com/security/cve/CVE-2022-4361 https://access.redhat.com/security/cve/CVE-2023-1108 https://access.redhat.com/security/cve/CVE-2023-1664 https://access.redhat.com/security/cve/CVE-2023-2422 https://access.redhat.com/security/cve/CVE-2023-2585 https://access.redhat.com/security/updates/classification/#important

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2023:3892-01
Product: Red Hat Single Sign-On
Issue date: 2023-06-27

Topic

A security update is now available for Red Hat Single Sign-On 7.6 from theCustomer Portal.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

1997772 - CVE-2021-39144 xstream: Arbitrary code execution via unsafe deserialization of sun.tracing.*

2151618 - CVE-2022-4361 Keycloak | RHSSO: XSS due to lax URI scheme validation

2174246 - CVE-2023-1108 Undertow: Infinite loop in SslConduit during close

2182196 - CVE-2023-1664 keycloak: Untrusted Certificate Validation

2191668 - CVE-2023-2422 keycloak: oauth client impersonation

2196335 - CVE-2023-2585 keycloak: client access via device auth request spoof

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here