Red Hat Security Advisory: Red Hat Single Sign-On 7.3.5 security update on RHEL 6
🔗 CVE IDs covered (6)
📋 Description
CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth CVE-2019-9515 — HTTP/2: flood using SETTINGS frames results in unbounded memory growth CVE-2019-14837 — keycloak: keycloak uses hardcoded open dummy domain for new accounts enabling information disclosure CVE-2019-14838 — wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default CVE-2019-14843 — wildfly-security-manager: security manager authorization bypass
🎯 Affected products4
- Red Hat Single Sign-On 7.3 for RHEL 6 Server
- rh-sso7-keycloak-0:4.8.15-1.Final_redhat_00001.1.el6sso.noarch as a component of Red Hat Single Sign-On 7.3 for RHEL 6 Server
- rh-sso7-keycloak-0:4.8.15-1.Final_redhat_00001.1.el6sso.src as a component of Red Hat Single Sign-On 7.3 for RHEL 6 Server
- rh-sso7-keycloak-server-0:4.8.15-1.Final_redhat_00001.1.el6sso.noarch as a component of Red Hat Single Sign-On 7.3 for RHEL 6 Server
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: It is not a very straight forward workaround but it is possible to mitigate this by manually editing the default Email ID ([email protected]) to some valid email ID ([email protected]) in the USER_ENTITY table in the RHSSO database used. Workaround: This flaw only affects the Security Manager running under JDK 11 or 8. To mitigate exposure to this flaw, do not run under those JDK versions.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2019:4040
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_single_sign-on/7.3/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1730227
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735745
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1751227
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1752980
- externalhttps://issues.redhat.com/browse/KEYCLOAK-11815
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_4040.json