RHSA-2018:2428HighCVSS 7.6

Red Hat Security Advisory: Red Hat Single Sign-On 7.2.4 security update

Published
August 15, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2017-12624 — cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services CVE-2018-8039 — apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* CVE-2018-10237 — guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service CVE-2018-10862 — wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) CVE-2018-10912 — keycloak: infinite loop in session replacement leading to denial of service CVE-2018-1000180 — bouncycastle: flaw in the low-level interface to RSA key pair generator

🎯 Affected products1

  • Red Hat Single Sign-On 7.2.4 zip

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).

🔗 References (11)