Lucene search

K
redhatRedHatRHSA-2024:1861
HistoryApr 16, 2024 - 7:48 p.m.

(RHSA-2024:1861) Important: Red Hat Single Sign-On 7.6.8 security update on RHEL 8

2024-04-1619:48:40
access.redhat.com
7
red hat single sign-on
rhel 8
security update
path traversal
cross-origin message
authorization bypass
log injection

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

8.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.

This release of Red Hat Single Sign-On 7.6.8 on RHEL 8 serves as a replacement for Red Hat Single Sign-On 7.6.7, and includes bug fixes, security updates and
enhancements which are linked to in the References.

Security Fix(es):

  • path transversal in redirection validation (CVE-2024-1132)

  • org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkLoginIframe leads to DDoS (CVE-2024-1249)

  • undertow: Out-of-memory Error after several closed connections with wildfly-http-client protocol (CVE-2024-1635)

  • Authorization Bypass (CVE-2023-6544)

  • Log Injection during WebAuthn authentication or registration (CVE-2023-6484)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in the
References section.

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

8.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%