Lucene search

K
redhatRedHatRHSA-2024:1860
HistoryApr 16, 2024 - 7:48 p.m.

(RHSA-2024:1860) Important: Red Hat Single Sign-On 7.6.8 enhancement and security update on RHEL 7

2024-04-1619:48:33
access.redhat.com
11
red hat single sign-on
rhel 7
keycloak project
authentication
single sign-on
bug fixes
security updates
cve-2023-6544
cve-2023-6484
cve-2024-1132
cve-2024-1249
cve-2024-1635
cvss score

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

8.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.

This release of Red Hat Single Sign-On 7.6.8 on RHEL 7 serves as a replacement for Red Hat Single Sign-On 7.6.7, and includes bug fixes, security updates and
enhancements which are linked to in the References.

Security Fix(es):

  • Authorization Bypass (CVE-2023-6544)
  • Log Injection during WebAuthn authentication or registration (CVE-2023-6484)
  • path transversal in redirection validation (CVE-2024-1132)
  • unvalidated cross-origin messages in checkLoginIframe leads to DDoS (CVE-2024-1249)
  • undertow: Out-of-memory Error after several closed connections with wildfly-http-client protocol (CVE-2024-1635)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

8.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%