RHSA-2018:3592MediumCVSS 6.1

Red Hat Security Advisory: Red Hat Single Sign-On 7.2.5 on RHEL 6 security and bug fix update

Published
November 13, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2018-10894 — keycloak: auth permitted with expired certs in SAML client CVE-2018-14637 — keycloak: expiration not validated in SAML broker consumer endpoint CVE-2018-14655 — keycloak: XSS-Vulnerability with response_mode=form_post CVE-2018-14657 — keycloak: brute force protection not working for the entire login workflow CVE-2018-14658 — keycloak: Open Redirect in Login and Logout

🎯 Affected products4

  • Red Hat Single Sign-On 7.2 for RHEL 6 Server
  • rh-sso7-keycloak-0:3.4.14-1.Final_redhat_00001.1.jbcs.el6.noarch as a component of Red Hat Single Sign-On 7.2 for RHEL 6 Server
  • rh-sso7-keycloak-0:3.4.14-1.Final_redhat_00001.1.jbcs.el6.src as a component of Red Hat Single Sign-On 7.2 for RHEL 6 Server
  • rh-sso7-keycloak-server-0:3.4.14-1.Final_redhat_00001.1.jbcs.el6.noarch as a component of Red Hat Single Sign-On 7.2 for RHEL 6 Server

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (9)