RHSA-2020:2112HighCVSS 8.8

Red Hat Security Advisory: Red Hat Single Sign-On 7.3.8 security update

Published
May 12, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2019-10172 — jackson-mapper-asl: XML external entity similar to CVE-2016-3720 CVE-2019-14900 — hibernate: SQL injection issue in Hibernate ORM CVE-2019-17573 — cxf: reflected XSS in the services listing page CVE-2020-1695 — resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class CVE-2020-1718 — keycloak: security issue on reset credential flow CVE-2020-1719 — Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain CVE-2020-1724 — keycloak: problem with privacy after user logout CVE-2020-1757 — undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass CVE-2020-1758 — keycloak: improper verification of certificate with host mismatch could result in information disclosure CVE-2020-7226 — cryptacular: excessive memory allocation during a decode operation

🎯 Affected products1

  • Red Hat Single Sign On 7.3.8

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: There is no currently known mitigation for this flaw. Workaround: Mitigate this flaw by disabling the service listing altogether; via setting the "hide-service-list-page" servlet parameter to "true". Workaround: Disable reset credential flow. Workaround: The issue can be mitigated by configuring UrlPathHelper to ignore the servletPath via setting "alwaysUseFullPath". Workaround: Turn off all kinds of email notifications including password reset mails.

🔗 References (15)