Red Hat Security Advisory: Red Hat Single Sign-On 7.2.4 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2017-12624 — cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services CVE-2018-8039 — apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* CVE-2018-10237 — guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service CVE-2018-10862 — wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) CVE-2018-10912 — keycloak: infinite loop in session replacement leading to denial of service CVE-2018-1000180 — bouncycastle: flaw in the low-level interface to RSA key pair generator
🎯 Affected products1
- Red Hat Single Sign-On 7.2.4 zip
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2018:2428
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=core.service.rhsso&version=7.2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_single_sign_on/?version=7.2
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1515976
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1573391
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1588306
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1593527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1595332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1607624
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_2428.json