An update is now available for Red Hat Single Sign-On 7.6 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Single Sign-On 7.6.1 security update Advisory ID: RHSA-2022:8965-01 Product: Red Hat Single Sign-On Advisory URL: https://access.redhat.com/errata/RHSA-2022:8965 Issue date: 2022-12-13 CVE Names: CVE-2022-3782 CVE-2022-3916 ==================================================================== 1. Summary: An update is now available for Red Hat Single Sign-On 7.6 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. This release of Red Hat Single Sign-On 7.6.1 serves as a replacement for Red Hat Single Sign-On 7.6.1, and includes the following security fixes. Security Fix(es): * keycloak: path traversal via double URL encoding (CVE-2022-3782) * keycloak: Session takeover with OIDC offline refreshtokens (CVE-2022-3916) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of thiserratum contains a download link (you must log in to download the update). 4. Bugs fixed (https://bugzilla.redhat.com/): 2138971 - CVE-2022-3782 keycloak: path traversal via double URL encoding 2141404 - CVE-2022-3916 keycloak: Session takeover with OIDC offline refreshtokens 5. JIRA issues fixed (https://issues.redhat.com/): CIAM-4411 - Build one-off patch 6. References: https://access.redhat.com/security/cve/CVE-2022-3782 https://access.redhat.com/security/cve/CVE-2022-3916 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=core.service.rhsso&downloadType=securityPatches&version=7.6 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY5ipmtzjgjWX9erEAQhu0A/8CC5j7AvyOc2vPpHVmT0KXrJVF1KGXsbB svAHX7hJHpp1aqCZReiC+b2v4TbCnVEt+k4od0XjgGrC5Wxk9gYz/crJ68m6qUIM N3z56OHqHZsNL4HZxIhw6dn4N7OisTidkHXGTZK3Y0HuVB+hGWy498OXsF/4kz7l SiJGuai0CtcF/g/u9fSYxuQUyQvuFDCDLrOXvaloBzhYgjLj43eoWBxlJ35br2U2 blsQdohT7t93LyT1g5TxE8Vc4iF/4/Tf6EjrmGK635XSAG5GzfHav0CnS9GU49Ju 3qA5Vvp9lJgEvq6kD4w0hyCkJ78aDK8ljK6NGZeyRRpXiAYJchvvXVJcKw2D1Fy2 FgqrEvWQqmiCw/z7Q9POXhOsz1xNwdy2bFjZtdOvrERSv1Ffn2vvQlInxcdq/WR2 AZ7vFV5AdLgPIwWosRiuOZXWl5smF5EsyyhsMdGzmiyZhhsEW1wAZ+8CUN3HEjxK 8QoNuLsgmOuDw4ga+NrZj8487m96RO/Tj1yqJ9eGLA2EFSOhJCunxP6atRUBeK1m diU0kJ5o3QnrzstmvYvNFJqS29aKAyiG8rOd2Il59BeHYRfd7tUiDAsRE5SQqh0h 6neuz4eqS19jrSCR4HgHsDRfbUcRQi/Rpuj1F9DM94in5TrQ0fUvuof2/xCZg1Q+ kb9RAWpgtBs=ov2Q -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for apache2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0888-1 Rating: important References: #1122839 #1131239 #1131241 Cross-References: CVE-2018-17199 CVE-2019-0217 CVE-2019-0220 Affected Products: SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for apache2 fixes the following issues: - CVE-2018-17199: A bug in Apache's "mod_session_cookie" lead to an issue where the module did not respect a cookie's expiry time. [bsc#1122839] * CVE-2019-0220: The Apache HTTP server did not use a consistent strategy for URL normalization throughout all of its components. In particular, consecutive slashes were not always collapsed. Attackers could potentially abuse these inconsistencies to by-pass access control mechanisms and thus gain unauthorized access to protected parts of the service. [bsc#1131241] * CVE-2019-0217: A race condition in Apache's "mod_auth_digest" when running in a threaded server could have allowed users with valid credentials to authenticate using another username, bypassing configured access control restrictions. [bsc#1131239] Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-888=1 Package List: - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): apache2-2.4.16-20.24.1 apache2-debuginfo-2.4.16-20.24.1 apache2-debugsource-2.4.16-20.24.1 apache2-example-pages-2.4.16-20.24.1 apache2-prefork-2.4.16-20.24.1 apache2-prefork-debuginfo-2.4.16-20.24.1 apache2-utils-2.4.16-20.24.1 apache2-utils-debuginfo-2.4.16-20.24.1 apache2-worker-2.4.16-20.24.1 apache2-worker-debuginfo-2.4.16-20.24.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (noarch): apache2-doc-2.4.16-20.24.1 References: https://www.suse.com/security/cve/CVE-2018-17199.html https://www.suse.com/security/cve/CVE-2019-0217.html https://www.suse.com/security/cve/CVE-2019-0220.html https://bugzilla.suse.com/1122839 https://bugzilla.suse.com/1131239 https://bugzilla.suse.com/1131241 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.