RHSA-2018:3595MediumCVSS 6.1

Red Hat Security Advisory: Red Hat Single Sign-On 7.2.5 security and bug fix update

Published
November 13, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2018-10894 — keycloak: auth permitted with expired certs in SAML client CVE-2018-14627 — JBoss/WildFly: iiop does not honour strict transport confidentiality CVE-2018-14637 — keycloak: expiration not validated in SAML broker consumer endpoint CVE-2018-14655 — keycloak: XSS-Vulnerability with response_mode=form_post CVE-2018-14657 — keycloak: brute force protection not working for the entire login workflow CVE-2018-14658 — keycloak: Open Redirect in Login and Logout

🎯 Affected products1

  • Red Hat Single Sign-On 7.2.5 zip

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).

🔗 References (12)