Lucene search

K
redhatRedHatRHSA-2024:3267
HistoryMay 22, 2024 - 10:41 a.m.

(RHSA-2024:3267) Moderate: idm:DL1 and idm:client security update

2024-05-2210:41:24
access.redhat.com
19
red hat; identity management; security update; jwcrypto; python-jwcrypto; denial of service; cve-2023-6681; cve-2024-28102; authentication; authorization; enterprise.

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

AI Score

7.2

Confidence

High

EPSS

0

Percentile

15.5%

Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Security Fix(es):

  • JWCrypto: denail of service Via specifically crafted JWE (CVE-2023-6681)

  • python-jwcrypto: malicious JWE token can cause denial of service (CVE-2024-28102)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

OSVersionArchitecturePackageVersionFilename
RedHatanyx86_64ipa-server-trust-ad-debuginfo< 4.9.13-9.module+el8.10.0+21691+df63127dipa-server-trust-ad-debuginfo-4.9.13-9.module+el8.10.0+21691+df63127d.x86_64.rpm
RedHatanyaarch64bind-dyndb-ldap-debuginfo< 11.6-5.module+el8.10.0+21691+df63127dbind-dyndb-ldap-debuginfo-11.6-5.module+el8.10.0+21691+df63127d.aarch64.rpm
RedHatanyaarch64ipa-debugsource< 4.9.13-9.module+el8.10.0+21692+c9b201bcipa-debugsource-4.9.13-9.module+el8.10.0+21692+c9b201bc.aarch64.rpm
RedHatanyppc64leipa-server-trust-ad-debuginfo< 4.9.13-9.module+el8.10.0+21691+df63127dipa-server-trust-ad-debuginfo-4.9.13-9.module+el8.10.0+21691+df63127d.ppc64le.rpm
RedHatanynoarchipa-client-common< 4.9.13-9.module+el8.10.0+21691+df63127dipa-client-common-4.9.13-9.module+el8.10.0+21691+df63127d.noarch.rpm
RedHatanys390xbind-dyndb-ldap< 11.6-5.module+el8.10.0+21691+df63127dbind-dyndb-ldap-11.6-5.module+el8.10.0+21691+df63127d.s390x.rpm
RedHatanyaarch64softhsm-debuginfo< 2.6.0-5.module+el8.9.0+18911+94941f82softhsm-debuginfo-2.6.0-5.module+el8.9.0+18911+94941f82.aarch64.rpm
RedHatanys390xipa-client-debuginfo< 4.9.13-9.module+el8.10.0+21691+df63127dipa-client-debuginfo-4.9.13-9.module+el8.10.0+21691+df63127d.s390x.rpm
RedHatanyx86_64bind-dyndb-ldap< 11.6-5.module+el8.10.0+21691+df63127dbind-dyndb-ldap-11.6-5.module+el8.10.0+21691+df63127d.x86_64.rpm
RedHatanys390xopendnssec-debuginfo< 2.1.7-1.module+el8.9.0+18911+94941f82opendnssec-debuginfo-2.1.7-1.module+el8.9.0+18911+94941f82.s390x.rpm
Rows per page:
1-10 of 1481

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

AI Score

7.2

Confidence

High

EPSS

0

Percentile

15.5%