RHSA-2023:3884HighCVSS 8.1

Red Hat Security Advisory: Red Hat Single Sign-On 7.6.4 security update on RHEL 8

Published
June 27, 2023
Last Modified
August 19, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2022-4361 — RHSSO: XSS due to lax URI scheme validation CVE-2023-1108 — Undertow: Infinite loop in SslConduit during close CVE-2023-1664 — keycloak: Untrusted Certificate Validation CVE-2023-2422 — keycloak: oauth client impersonation CVE-2023-2585 — keycloak: client access via device auth request spoof

🎯 Affected products4

  • Red Hat Single Sign-On 7.6 for RHEL 8
  • rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el8sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 8
  • rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el8sso.src as a component of Red Hat Single Sign-On 7.6 for RHEL 8
  • rh-sso7-keycloak-server-0:18.0.8-1.redhat_00001.1.el8sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Make sure KC_SPI_TRUSTSTORE_FILE_FILE is correctly set and the logs are not reporting the "Cannot validate client certificate trust: Truststore not available" after an attempt to explore the vulnerability. Note this message may happen under other scenarios and reasons but the expected behavior would be that a non-valid certificate to pass.

🔗 References (9)