RHSA-2023:3888HighCVSS 8.1

Red Hat Security Advisory: Red Hat Single Sign-On 7.6.4 for OpenShift image security enhancement update

Published
June 27, 2023
Last Modified
August 19, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2022-4361 — RHSSO: XSS due to lax URI scheme validation CVE-2023-1108 — Undertow: Infinite loop in SslConduit during close CVE-2023-1664 — keycloak: Untrusted Certificate Validation CVE-2023-2422 — keycloak: oauth client impersonation CVE-2023-2585 — keycloak: client access via device auth request spoof

🎯 Affected products4

  • Middleware Containers for OpenShift
  • rh-sso-7/sso76-openshift-rhel8@sha256:b8452b9ca79791555bb4709a4d3c81768e0571f72fe88480be9dfd585e02913e_s390x as a component of Middleware Containers for OpenShift
  • rh-sso-7/sso76-openshift-rhel8@sha256:d15acb2c2c6bed9934c011c6864ca5c2ae989f783390bdb3eca77f5fc4ccc92a_amd64 as a component of Middleware Containers for OpenShift
  • rh-sso-7/sso76-openshift-rhel8@sha256:f52cb785c11ab691e0583a69e665496af83b4191037742ef2b1dd1237f42722e_ppc64le as a component of Middleware Containers for OpenShift

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Make sure KC_SPI_TRUSTSTORE_FILE_FILE is correctly set and the logs are not reporting the "Cannot validate client certificate trust: Truststore not available" after an attempt to explore the vulnerability. Note this message may happen under other scenarios and reasons but the expected behavior would be that a non-valid certificate to pass.

🔗 References (8)