RHSA-2021:5170MediumCVSS 7.8

Red Hat Security Advisory: Red Hat Single Sign-On 7.4.10 security update

Published
December 15, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2021-3629 — undertow: potential security issue in flow control over HTTP/2 may lead to DOS CVE-2021-3642 — wildfly-elytron: possible timing attack in ScramServer CVE-2021-3717 — wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-37714 — jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck CVE-2021-40690 — xml-security: XPath Transform abuse allows for information disclosure

🎯 Affected products1

  • Red Hat Single Sign-On 7.4.10

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).

🔗 References (12)