RHSA-2024:1861: Important: Red Hat Single Sign-On 7.6.8 security update on RHEL 8
Important: Red Hat Single Sign-On 7.6.8 security update on RHEL 8
Other sources
Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.<br>This release of Red Hat Single Sign-On 7.6.8 on RHEL 8 serves as a replacement for Red Hat Single Sign-On 7.6.7, and includes bug fixes, security updates and<br>enhancements which are linked to in the References.<br>Security Fix(es):<br><li> path transversal in redirection validation (CVE-2024-1132)</li> <li> org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkLoginIframe leads to DDoS (CVE-2024-1249)</li> <li> undertow: Out-of-memory Error after several closed connections with wildfly-http-client protocol (CVE-2024-1635)</li> <li> Authorization Bypass (CVE-2023-6544)</li> <li> Log Injection during WebAuthn authentication or registration (CVE-2023-6484)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, and other related information, refer to the CVE page(s) listed in the<br>References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1861?
The severity of RHSA-2024:1861 is classified as important.
What products are affected by RHSA-2024:1861?
RHSA-2024:1861 affects Red Hat Single Sign-On 7.6.8, specifically versions related to rh-sso7-keycloak and rh-sso7-keycloak-server packages.
How do I fix RHSA-2024:1861?
To fix RHSA-2024:1861, you need to update to rh-sso7-keycloak and rh-sso7-keycloak-server version 18.0.13-1.redhat_00001.1.el8.
Is RHSA-2024:1861 a critical vulnerability?
No, RHSA-2024:1861 is not classified as a critical vulnerability but is considered important.
What is Red Hat Single Sign-On 7.6.8 used for?
Red Hat Single Sign-On 7.6.8 provides authentication and standards-based single sign-on capabilities for web and mobile applications.