RHSA-2023:4918HighCVSS 7.5

Red Hat Security Advisory: Red Hat Single Sign-On 7.6.5 security update on RHEL 7

Published
August 31, 2023
Last Modified
August 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2021-46877 — jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode CVE-2023-1436 — jettison: Uncontrolled Recursion in JSONArray CVE-2023-3223 — undertow: OutOfMemoryError due to @MultipartConfig handling

🎯 Affected products4

  • Red Hat Single Sign-On 7.6 for RHEL 7 Server
  • rh-sso7-keycloak-0:18.0.9-1.redhat_00001.1.el7sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 7 Server
  • rh-sso7-keycloak-0:18.0.9-1.redhat_00001.1.el7sso.src as a component of Red Hat Single Sign-On 7.6 for RHEL 7 Server
  • rh-sso7-keycloak-server-0:18.0.9-1.redhat_00001.1.el7sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 7 Server

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (6)