RHSA-2023:4921HighCVSS 7.5

Red Hat Security Advisory: Red Hat Single Sign-On 7.6.5 for OpenShift image enhancement and security update

Published
August 31, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2021-46877 — jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode CVE-2023-1436 — jettison: Uncontrolled Recursion in JSONArray CVE-2023-3223 — undertow: OutOfMemoryError due to @MultipartConfig handling

🎯 Affected products4

  • Middleware Containers for OpenShift
  • rh-sso-7/sso76-openshift-rhel8@sha256:1a8c42f880d58f68682d4b42b208789ac4d3cedf1fa025c8bfb980a16e707528_amd64 as a component of Middleware Containers for OpenShift
  • rh-sso-7/sso76-openshift-rhel8@sha256:49034f0279b90c0f7979f005f823ab2d6e5cb5a1638d0258ab22834b7b4f225a_s390x as a component of Middleware Containers for OpenShift
  • rh-sso-7/sso76-openshift-rhel8@sha256:6062a78f9392681ec777bcec7a2105d6e1cca1ee905828590f5ba2e07921c16b_ppc64le as a component of Middleware Containers for OpenShift

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (6)