Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

Red Hat Single Sign-On 7.6.4: RHSA-2023:3892-01 Important Security Update

A security update is now available for Red Hat Single Sign-On 7.6 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Single Sign-On 7.6.4 security update Advisory ID: RHSA-2023:3892-01 Product: Red Hat Single Sign-On Advisory URL: https://access.redhat.com/errata/RHSA-2023:3892 Issue date: 2023-06-27 CVE Names: CVE-2021-39144 CVE-2022-4361 CVE-2023-1108 CVE-2023-1664 CVE-2023-2422 CVE-2023-2585 ==================================================================== 1. Summary: A security update is now available for Red Hat Single Sign-On 7.6 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. This release of Red Hat Single Sign-On 7.6.4 serves as a replacement for Red Hat Single Sign-On 7.6.3, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * keycloak: Cross-site scripting when validating URI-schemes on SAML and OIDC (CVE-2022-4361) * keycloak: oauth client impersonation (CVE-2023-2422) * keycloak: Untrusted Certificate Validation (CVE-2023-1664) * undertow: Infinite loop in SslConduit during close (CVE-2023-1108) * keycloak: client access via device auth request spoof (CVE-2023-2585) * xstream:Arbitrary code execution via unsafe deserialization of sun.tracing.* (CVE-2021-39144) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 1997772 - CVE-2021-39144 xstream: Arbitrary code execution via unsafe deserialization of sun.tracing.* 2151618 - CVE-2022-4361 Keycloak | RHSSO: XSS due to lax URI scheme validation 2174246 - CVE-2023-1108 Undertow: Infinite loop in SslConduit during close 2182196 - CVE-2023-1664 keycloak: Untrusted Certificate Validation 2191668 - CVE-2023-2422 keycloak: oauth client impersonation 2196335 - CVE-2023-2585 keycloak: client access via device auth request spoof 5. References: https://access.redhat.com/security/cve/CVE-2021-39144 https://access.redhat.com/security/cve/CVE-2022-4361 https://access.redhat.com/security/cve/CVE-2023-1108 https://access.redhat.com/security/cve/CVE-2023-1664 https://access.redhat.com/security/cve/CVE-2023-2422 https://access.redhat.com/security/cve/CVE-2023-2585 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZJtZltzjgjWX9erEAQjp7w/+PVnQj3iscLy7t8uh2ALC/EOE+uD+oOZl sDUfI7n5uPLq1NidzM2PL7jc1fEIYHVZfU8siqOZCkKXkb+QG0rxliynGbggvQCW KpcgN6kFk94nF9h1TGGdXAvo+POj3dWy98Vl6+i2lwYWro3WeWl+Szayr8FjNXPp 0dS6hAQQt889edUgYj5s2tpSfaYQNqLhKNNnjyJKrWr8k3qpc+Va1A/i2eXeXDdr O6esc6NE4apHmKFc9rWMSlct8Yzi37K+dCybjgI+u93tOwB8N4DWtBun27DagQYB Cc3GTgWyczMSKBNi6e9C86VvJ1c5jvAQ5DIJ1ez+OO41D6qQkhwtg8WG7GIF/MFH LcdOfk4arzEsVd1G5vkU/tiGRUChUeyu9xm7k57M/454qP5AmDUdPQSvgqmgWwBM cwKx0YkxMl5qSRSVDxEjD9CzcfDz6b+YvTxaFb8C3IRUhYwsuoy7kdMJ8vuY6rj0 IDAJ7zC1sVb5FKR4E23Fp9Ma7M0+lUV87Y3UF1fE1pswQQ/aJu2q3k+N5PLM+9A7 q2ZhNEic6CBU8DoRBeU/JVM8j+bEgM17Bf98A1rebQdfLQ8Dd2sF7ngEuO7dLGgD LNqaHScdEl14Nq6xAUV5VmjKq+k4n+nWfl20aFddDH9b1afhlmAR55SNvK75Eud3 prjQ1em3Iw8=qI1p -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Keep up to date with essential news regarding security in Red Hat Single Sign-On 7.6.4. Critical information found within the advisory.. Red Hat Single Sign-On, Authentication Update, Important Patch, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 27, 2023 Important Red Hat
219

Rocky Linux 8 RLSA-2021:1983 Important IdM Security Flaws

Important: idm:DL1 security update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2021:1983', 'synopsis': 'Important: idm:DL1 security update', 'severity': 'Important', 'topic': 'An update for the idm:DL1 module is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'Rocky Linux Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments. \nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1944640'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-3480.json:::CVE-2021-3480'], 'references': [], 'publishedAt': '2021-07-22T03:17:05.792932Z', 'rpms': ['ipa-4.9.2-3.module+el8.4.0+590+61daf22b.src.rpm', 'ipa-client-4.9.2-3.module+el8.4.0+590+61daf22b.aarch64.rpm', 'ipa-client-4.9.2-3.module+el8.4.0+590+61daf22b.x86_64.rpm', 'ipa-client-common-4.9.2-3.module+el8.4.0+590+61daf22b.noarch.rpm', 'ipa-client-debuginfo-4.9.2-3.module+el8.4.0+590+61daf22b.aarch64.rpm', 'ipa-client-debuginfo-4.9.2-3.module+el8.4.0+590+61daf22b.x86_64.rpm', 'ipa-client-epn-4.9.2-3.module+el8.4.0+590+61daf22b.aarch64.rpm', 'ipa-client-epn-4.9.2-3.module+el8.4.0+590+61daf22b.x86_64.rpm', 'ipa-client-samba-4.9.2-3.module+el8.4.0+590+61daf22b.aarch64.rpm', 'ipa-client-samba-4.9.2-3.module+el8.4.0+590+61daf22b.x86_64.rpm', 'ipa-common-4.9.2-3.module+el8.4.0+590+61daf22b.noarch.rpm', 'ipa-debuginfo-4.9.2-3.module+el8.4.0+590+61daf22b.aarch64.rpm', 'ipa-debuginfo-4.9.2-3.module+el8.4.0+590+61daf22b.x86_64.rpm','ipa-debugsource-4.9.2-3.module+el8.4.0+590+61daf22b.aarch64.rpm', 'ipa-debugsource-4.9.2-3.module+el8.4.0+590+61daf22b.x86_64.rpm', 'ipa-healthcheck-0.7-3.module+el8.4.0+430+1dcf16bb.src.rpm', 'ipa-healthcheck-core-0.7-3.module+el8.4.0+430+1dcf16bb.noarch.rpm', 'ipa-python-compat-4.9.2-3.module+el8.4.0+590+61daf22b.noarch.rpm', 'ipa-selinux-4.9.2-3.module+el8.4.0+590+61daf22b.noarch.rpm', 'python3-ipaclient-4.9.2-3.module+el8.4.0+590+61daf22b.noarch.rpm', 'python3-ipalib-4.9.2-3.module+el8.4.0+590+61daf22b.noarch.rpm', 'python3-jwcrypto-0.5.0-1.module+el8.4.0+430+1dcf16bb.noarch.rpm', 'python3-kdcproxy-0.4-5.module+el8.3.0+244+0b2ae752.noarch.rpm', 'python3-pyusb-1.0.0-9.module+el8.4.0+430+1dcf16bb.noarch.rpm', 'python3-yubico-1.3.2-9.module+el8.4.0+430+1dcf16bb.noarch.rpm', 'python-jwcrypto-0.5.0-1.module+el8.4.0+430+1dcf16bb.src.rpm', 'python-kdcproxy-0.4-5.module+el8.3.0+244+0b2ae752.src.rpm', 'python-yubico-1.3.2-9.module+el8.4.0+430+1dcf16bb.src.rpm', 'pyusb-1.0.0-9.module+el8.4.0+430+1dcf16bb.src.rpm', 'slapi-nis-0.56.6-2.module+el8.4.0+429+6bd33fea.aarch64.rpm', 'slapi-nis-0.56.6-2.module+el8.4.0+429+6bd33fea.src.rpm', 'slapi-nis-0.56.6-2.module+el8.4.0+429+6bd33fea.x86_64.rpm', 'slapi-nis-debuginfo-0.56.6-2.module+el8.4.0+429+6bd33fea.aarch64.rpm', 'slapi-nis-debuginfo-0.56.6-2.module+el8.4.0+429+6bd33fea.x86_64.rpm', 'slapi-nis-debugsource-0.56.6-2.module+el8.4.0+429+6bd33fea.aarch64.rpm', 'slapi-nis-debugsource-0.56.6-2.module+el8.4.0+429+6bd33fea.x86_64.rpm']}\. CentOS Stream XEN:AZ8 security patch mitigates severe vulnerabilities, enhancing user account management systems. Remain protected!. Rocky Linux Update, IdM Security, Authentication Updates, Security Management. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 02, 2022 Important Rocky Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here