RHSA-2024:1860: Important: Red Hat Single Sign-On 7.6.8 enhancement and security update on RHEL 7
Important: Red Hat Single Sign-On 7.6.8 enhancement and security update on RHEL 7
Other sources
Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.This release of Red Hat Single Sign-On 7.6.8 on RHEL 7 serves as a replacement for Red Hat Single Sign-On 7.6.7, and includes bug fixes, security updates andenhancements which are linked to in the References.Security Fix(es): Authorization Bypass (CVE-2023-6544) Log Injection during WebAuthn authentication or registration (CVE-2023-6484) path transversal in redirection validation (CVE-2024-1132) unvalidated cross-origin messages in checkLoginIframe leads to DDoS (CVE-2024-1249) undertow: Out-of-memory Error after several closed connections with wildfly-http-client protocol (CVE-2024-1635) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1860?
The severity of RHSA-2024:1860 is classified as important.
How do I fix RHSA-2024:1860?
To fix RHSA-2024:1860, update to the package versions 18.0.13-1.redhat_00001.1.el7 for rh-sso7-keycloak and rh-sso7-keycloak-server.
Which products are affected by RHSA-2024:1860?
The affected products include Red Hat Single Sign-On 7.6 and its Keycloak packages on RHEL 7.
What enhancements are included in RHSA-2024:1860?
RHSA-2024:1860 includes security updates and enhancements for Red Hat Single Sign-On 7.6.8.
Is there any risk if I don't address RHSA-2024:1860?
Failure to address RHSA-2024:1860 could expose your system to potential security vulnerabilities and exploitations.