RHSA-2018:3593MediumCVSS 6.1
Red Hat Security Advisory: Red Hat Single Sign-On 7.2.5 on RHEL 7 security and bug fix update
🔗 CVE IDs covered (5)
📋 Description
CVE-2018-10894 — keycloak: auth permitted with expired certs in SAML client CVE-2018-14637 — keycloak: expiration not validated in SAML broker consumer endpoint CVE-2018-14655 — keycloak: XSS-Vulnerability with response_mode=form_post CVE-2018-14657 — keycloak: brute force protection not working for the entire login workflow CVE-2018-14658 — keycloak: Open Redirect in Login and Logout
🎯 Affected products4
- Red Hat Single Sign-On 7.2 for RHEL 7 Server
- rh-sso7-keycloak-0:3.4.14-1.Final_redhat_00001.1.jbcs.el7.noarch as a component of Red Hat Single Sign-On 7.2 for RHEL 7 Server
- rh-sso7-keycloak-0:3.4.14-1.Final_redhat_00001.1.jbcs.el7.src as a component of Red Hat Single Sign-On 7.2 for RHEL 7 Server
- rh-sso7-keycloak-server-0:3.4.14-1.Final_redhat_00001.1.jbcs.el7.noarch as a component of Red Hat Single Sign-On 7.2 for RHEL 7 Server
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2018:3593
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_single_sign_on/?version=7.2
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1599434
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1625396
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1625404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1625409
- externalhttps://issues.redhat.com/browse/JBEAP-15588
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_3593.json