RHSA-2023:3892HighCVSS 8.5

Red Hat Security Advisory: Red Hat Single Sign-On 7.6.4 security update

Published
June 27, 2023
Last Modified
August 19, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2021-39144 — xstream: Arbitrary code execution via unsafe deserialization of sun.tracing.* CVE-2022-4361 — RHSSO: XSS due to lax URI scheme validation CVE-2023-1108 — Undertow: Infinite loop in SslConduit during close CVE-2023-1664 — keycloak: Untrusted Certificate Validation CVE-2023-2422 — keycloak: oauth client impersonation CVE-2023-2585 — keycloak: client access via device auth request spoof

🎯 Affected products1

  • Red Hat Single Sign-On 7

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Make sure KC_SPI_TRUSTSTORE_FILE_FILE is correctly set and the logs are not reporting the "Cannot validate client certificate trust: Truststore not available" after an attempt to explore the vulnerability. Note this message may happen under other scenarios and reasons but the expected behavior would be that a non-valid certificate to pass.

🔗 References (9)