RHSA-2020:4932: Moderate: Red Hat Single Sign-On 7.4.3 security update on RHEL 8
Red Hat Single Sign-On 7.4 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.<br>This release of Red Hat Single Sign-On 7.4.3 security update on RHEL 8 serves as a replacement for Red Hat Single Sign-On 7.4.2, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> keycloak: user can manage resources with just "view-profile" role using new Account Console (CVE-2020-14389)</li> <li> keycloak: OIDC redirecturi allows dangerous schemes resulting in potential XSS (CVE-2020-10776)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4932?
The severity of RHSA-2020:4932 is classified as moderate.
How do I fix RHSA-2020:4932?
To fix RHSA-2020:4932, update the affected packages to their latest versions as specified by Red Hat.
What software does RHSA-2020:4932 affect?
RHSA-2020:4932 affects Red Hat Single Sign-On 7.4 and related packages like rh-sso7-keycloak and rh-sso7-libunix-dbus-java.
When was RHSA-2020:4932 released?
RHSA-2020:4932 was released on December 8, 2020.
Is there a known issue related to RHSA-2020:4932?
Yes, there are known issues detailed in Bugzilla reports linked to RHSA-2020:4932.