First published: Tue Dec 15 2020(Updated: )
Red Hat Single Sign-On is an integrated sign-on solution, available as a Red Hat JBoss Middleware for OpenShift containerized image. The Red Hat Single Sign-On for OpenShift image provides an authentication server that you can use to log in centrally, log out, and register. You can also manage user accounts for web applications, mobile applications, and RESTful web services.<br>This erratum releases a new image for Red Hat Single Sign-On 7.4.4 on OpenJDK for operation within the OpenShift Container Platform of versions 3.10, 3.11, up to the 4.6 cloud computing Platform-as-a-Service (PaaS) for on-premise or private cloud deployments, aligning with the standalone product release.<br>Security Fix(es):<br><li> containers/redhat-sso-7: /etc/passwd is given incorrect privileges (CVE-2020-10695)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Single Sign On | ||
Red Hat OpenShift Container Platform for IBM LinuxONE | <=4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:5529 is classified as moderate.
To fix RHSA-2020:5529, you should apply the recommended updates for Red Hat Single Sign-On and Red Hat OpenShift Container Platform.
RHSA-2020:5529 affects Red Hat Single Sign-On and Red Hat OpenShift Container Platform versions up to 4.6.
RHSA-2020:5529 impacts Red Hat Single Sign-On and Red Hat OpenShift Container Platform.
There are no documented workarounds for RHSA-2020:5529, so patching is advised.