RHSA-2024:3574: Low: Red Hat build of Keycloak 22.0.11 enhancement and security update
Low: Red Hat build of Keycloak 22.0.11 enhancement and security update
Other sources
Red Hat build of Keycloak 22.0.11 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.<br>This release of Red Hat build of Keycloak 22.0.11 serves as a replacement for Red Hat Single Sign-On 7.6, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> exposure of sensitive information in Pushed Authorization Requests (PAR)</li> KCRESTART cookie (CVE-2024-4540)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s)<br>listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3574?
The severity of RHSA-2024:3574 is classified as low.
How do I fix RHSA-2024:3574?
To fix RHSA-2024:3574, you should upgrade to the latest version of Red Hat build of Keycloak.
What vulnerabilities are addressed in RHSA-2024:3574?
RHSA-2024:3574 addresses enhancement and security updates for the Red Hat build of Keycloak.
Which products are affected by RHSA-2024:3574?
The affected product for RHSA-2024:3574 is the Red Hat build of Keycloak version 22.0.11.
Is RHSA-2024:3574 related to authentication issues?
Yes, RHSA-2024:3574 pertains to the Red Hat build of Keycloak, which provides authentication and single sign-on capabilities.