RHSA-2018:3595MediumCVSS 6.1
Red Hat Security Advisory: Red Hat Single Sign-On 7.2.5 security and bug fix update
🔗 CVE IDs covered (6)
📋 Description
CVE-2018-10894 — keycloak: auth permitted with expired certs in SAML client CVE-2018-14627 — JBoss/WildFly: iiop does not honour strict transport confidentiality CVE-2018-14637 — keycloak: expiration not validated in SAML broker consumer endpoint CVE-2018-14655 — keycloak: XSS-Vulnerability with response_mode=form_post CVE-2018-14657 — keycloak: brute force protection not working for the entire login workflow CVE-2018-14658 — keycloak: Open Redirect in Login and Logout
🎯 Affected products1
- Red Hat Single Sign-On 7.2.5 zip
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2018:3595
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=core.service.rhsso&version=7.2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_single_sign_on/?version=7.2
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1599434
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1624664
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1625396
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1625404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1625409
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1627851
- externalhttps://issues.redhat.com/browse/JBEAP-15587
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_3595.json