Lucene search

K
redhatRedHatRHSA-2023:7488
HistoryNov 24, 2023 - 4:56 p.m.

(RHSA-2023:7488) Important: Red Hat Single Sign-On 7.6.6 security update

2023-11-2416:56:27
access.redhat.com
28
red hat single sign-on
keycloak
authentication
standards-based
web applications
mobile applications
security update
ddos attack
http/2
rapid reset attack
ldap injection attack
self-signed certificate
impersonation
lockout
cve page

7.9 High

AI Score

Confidence

Low

0.732 High

EPSS

Percentile

98.1%

Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.

This release of Red Hat Single Sign-On 7.6.6 serves as a replacement for Red Hat Single Sign-On 7.6.5, and includes bug fixes and enhancements.

Security Fix(es):

  • undertow: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
  • netty-codec-http2: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
  • bouncycastle: potential blind LDAP injection attack using a self-signed certificate (CVE-2023-33201)
  • keycloak: impersonation and lockout possible through incorrect handling of email trust (CVE-2023-0105)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.