First published: Wed Mar 01 2023(Updated: )
Red Hat Single Sign-On is an integrated sign-on solution, available as a<br>Red Hat JBoss Middleware for OpenShift containerized image. The Red Hat<br>Single Sign-On for OpenShift image provides an authentication server that<br>you can use to log in centrally, log out, and register. You can also manage<br>user accounts for web applications, mobile applications, and RESTful web<br>services.<br><li> snakeyaml: Constructor Deserialization Remote Code Execution (CVE-2022-1471)</li> <li> keycloak: path traversal via double URL encoding (CVE-2022-3782)</li> <li> RH-SSO for OpenShift images: unsecured management interface exposed to adjacent network (CVE-2022-4039)</li> <li> snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857)</li> <li> moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129)</li> <li> sshd-common: mina-sshd: Java unsafe deserialization vulnerability (CVE-2022-45047)</li> <li> CXF: Apache CXF: SSRF Vulnerability (CVE-2022-46364)</li> <li> keycloak: keycloak: user impersonation via stolen uuid code (CVE-2023-0264)</li> <li> bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040)</li> <li> rcue-bootstrap: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip (CVE-2018-14042)</li> <li> jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358)</li> <li> jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)</li> <li> keycloak: glob-parent: Regular Expression Denial of Service (CVE-2021-35065)</li> <li> keycloak: minimist: prototype pollution (CVE-2021-44906)</li> <li> keycloak: missing email notification template allowlist (CVE-2022-1274)</li> <li> keycloak: XSS on izmpersonation under specific circumstances (CVE-2022-1438)</li> <li> keycloak: Session takeover with OIDC offline refreshtokens (CVE-2022-3916)</li> <li> Moment.js: Path traversal in moment.locale (CVE-2022-24785)</li> <li> loader-utils: loader-utils:Regular expression denial of service (CVE-2022-37603)</li> <li> snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode (CVE-2022-38749)</li> <li> snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject (CVE-2022-38750)</li> <li> snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match (CVE-2022-38751)</li> <li> jettison: parser crash by stackoverflow (CVE-2022-40149)</li> <li> jettison: memory exhaustion via user-supplied XML or JSON data (CVE-2022-40150)</li> <li> jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos (CVE-2022-45693)</li> <li> json5: Prototype Pollution in JSON5 via Parse Method (CVE-2022-46175)</li> <li> jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS (CVE-2022-42003)</li> <li> jackson-databind: use of deeply nested arrays (CVE-2022-42004)</li> <li> CXF: Apache CXF: directory listing / code exfiltration (CVE-2022-46363)</li> <li> undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations (CVE-2022-2764)</li> <li> keycloak: Client Registration endpoint does not check token revocation (CVE-2023-0091)</li> This erratum releases a new image for Red Hat Single Sign-On 7.6.2 for use<br>within the Red Hat OpenShift Container Platform (from the release of 3.11<br>up to the release of 4.12.0) cloud computing Platform-as-a-Service (PaaS)<br>for on-premise or private cloud deployments, aligning with the standalone<br>product release.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.