Red Hat Security Advisory: Red Hat Single Sign-On 7.3.8 security update
🔗 CVE IDs covered (10)
📋 Description
CVE-2019-10172 — jackson-mapper-asl: XML external entity similar to CVE-2016-3720 CVE-2019-14900 — hibernate: SQL injection issue in Hibernate ORM CVE-2019-17573 — cxf: reflected XSS in the services listing page CVE-2020-1695 — resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class CVE-2020-1718 — keycloak: security issue on reset credential flow CVE-2020-1719 — Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain CVE-2020-1724 — keycloak: problem with privacy after user logout CVE-2020-1757 — undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass CVE-2020-1758 — keycloak: improper verification of certificate with host mismatch could result in information disclosure CVE-2020-7226 — cryptacular: excessive memory allocation during a decode operation
🎯 Affected products1
- Red Hat Single Sign On 7.3.8
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: There is no currently known mitigation for this flaw. Workaround: Mitigate this flaw by disabling the service listing altogether; via setting the "hide-service-list-page" servlet parameter to "true". Workaround: Disable reset credential flow. Workaround: The issue can be mitigated by configuring UrlPathHelper to ignore the servletPath via setting "alwaysUseFullPath". Workaround: Turn off all kinds of email notifications including password reset mails.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2020:2112
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=core.service.rhsso&downloadType=securityPatches&version=7.3
- externalhttps://access.redhat.com/documentation/en-us/red_hat_single_sign-on/7.3/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666499
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1715075
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1730462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1752770
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1796617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1796756
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797011
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1800527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1801380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1812514
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2112.json