Red Hat Security Advisory: Red Hat Single Sign-On 7.6.6 for OpenShift image enhancement and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-6927 — keycloak: open redirect via "form_post.jwt" JARM response mode
🎯 Affected products5
- Middleware Containers for OpenShift
- rh-sso-7/sso7-rhel8-operator-bundle@sha256:438375181ff28d5a61510a07f6e16d11944ebd6cc0a20961e06f662db3a16b1c_amd64 as a component of Middleware Containers for OpenShift
- rh-sso-7/sso76-openshift-rhel8@sha256:1f39a66794485f27da60afe31e8c7f5db5ece4bcf5a457ee7bad4a72ee70ce2e_amd64 as a component of Middleware Containers for OpenShift
- rh-sso-7/sso76-openshift-rhel8@sha256:7b10d4158944fd6c65f16c8b8cd57fb45c7a8c2cc0528bcce127218368ba41c3_s390x as a component of Middleware Containers for OpenShift
- rh-sso-7/sso76-openshift-rhel8@sha256:b145d1c7d0939d5b44234e2a9fbe7d0aba7b579e4aaf2c4977f8fde6aa97bff2_ppc64le as a component of Middleware Containers for OpenShift
✅ Remediation
To update to the latest Red Hat Single Sign-On 7.6.6 for OpenShift image, follow these steps to pull in the content: 1. On your main hosts, ensure you are logged into the CLI as a cluster administrator or user with project administrator access to the global "openshift" project. For example: $ oc login -u system:admin 2. Update the core set of Red Hat Single Sign-On resources for OpenShift in the "openshift" project by running the following commands: $ for resource in sso76-image-stream.json \ sso76-https.json \ sso76-mysql.json \ sso76-mysql-persistent.json \ sso76-postgresql.json \ sso76-postgresql-persistent.json \ sso76-x509-https.json \ sso76-x509-mysql-persistent.json \ sso76-x509-postgresql-persistent.json do oc replace -n openshift --force -f \ https://raw.githubusercontent.com/jboss-container-images/redhat-sso-7-openshift-image/v7.6.6.GA/templates/${resource} done 3. Install the Red Hat Single Sign-On 7.6.6 for OpenShift streams in the "openshift" project by running the following command: $ oc -n openshift import-image redhat-sso76-openshift:1.0 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.