Red Hat Security Advisory: Red Hat Single Sign-On 7.6.4 security update on RHEL 8
🔗 CVE IDs covered (5)
📋 Description
CVE-2022-4361 — RHSSO: XSS due to lax URI scheme validation CVE-2023-1108 — Undertow: Infinite loop in SslConduit during close CVE-2023-1664 — keycloak: Untrusted Certificate Validation CVE-2023-2422 — keycloak: oauth client impersonation CVE-2023-2585 — keycloak: client access via device auth request spoof
🎯 Affected products4
- Red Hat Single Sign-On 7.6 for RHEL 8
- rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el8sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 8
- rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el8sso.src as a component of Red Hat Single Sign-On 7.6 for RHEL 8
- rh-sso7-keycloak-server-0:18.0.8-1.redhat_00001.1.el8sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Make sure KC_SPI_TRUSTSTORE_FILE_FILE is correctly set and the logs are not reporting the "Cannot validate client certificate trust: Truststore not available" after an attempt to explore the vulnerability. Note this message may happen under other scenarios and reasons but the expected behavior would be that a non-valid certificate to pass.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2023:3884
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/articles/11258
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151618
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2174246
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182196
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2191668
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196335
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3884.json