Red Hat Security Advisory: Red Hat Single Sign-On 7.5.3 security update on RHEL 7
🔗 CVE IDs covered (8)
📋 Description
CVE-2020-36518 — jackson-databind: denial of service via a large depth of nested objects CVE-2021-42392 — h2: Remote Code Execution in Console CVE-2021-43797 — netty: control chars in header names may lead to HTTP request smuggling CVE-2022-0084 — xnio: org.xnio.StreamConnection.notifyReadClosed log to debug instead of stderr CVE-2022-0225 — keycloak: Stored XSS in groups dropdown CVE-2022-0866 — wildfly: Wildfly management of EJB Session context returns wrong caller principal with Elytron Security enabled CVE-2022-2256 — keycloak: improper input validation permits script injection CVE-2022-2668 — keycloak: Uploading of SAML javascript protocol mapper scripts through the admin console
🎯 Affected products4
- Red Hat Single Sign-On 7.5 for RHEL 7 Server
- rh-sso7-keycloak-0:15.0.8-1.redhat_00001.1.el7sso.noarch as a component of Red Hat Single Sign-On 7.5 for RHEL 7 Server
- rh-sso7-keycloak-0:15.0.8-1.redhat_00001.1.el7sso.src as a component of Red Hat Single Sign-On 7.5 for RHEL 7 Server
- rh-sso7-keycloak-server-0:15.0.8-1.redhat_00001.1.el7sso.noarch as a component of Red Hat Single Sign-On 7.5 for RHEL 7 Server
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: In order to avoid the possibility of information access, review application source code for '@RunAs' and 'run-as-principal' usage. Also, make sure the application is using or not Elytron Security. It's possible to investigate by checking if the commands from '$JBOSS_HOME/docs/examples/enable-elytron.cli' or similar were executed.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2022:6782
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031958
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039403
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040268
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2060929
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064226
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064698
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2101942
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2115392
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6782.json