RHSA-2024:0100MediumCVSS 4.6
Red Hat Security Advisory: Red Hat build of Keycloak 22.0.8 images enhancement and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-6927 — keycloak: open redirect via "form_post.jwt" JARM response mode
🎯 Affected products8
- Red Hat build of Keycloak 22
- rhbk/keycloak-operator-bundle@sha256:47323bf5e0d1ec70bfec6d7dd476d1076d879d26cc166af451579e79a56046ec_amd64 as a component of Red Hat build of Keycloak 22
- rhbk/keycloak-rhel9-operator@sha256:32817f8250713ae02ef6a1c6837298032ca49b27ff4af3c35c9bb763ad47ba75_s390x as a component of Red Hat build of Keycloak 22
- rhbk/keycloak-rhel9-operator@sha256:b24d774edf776b6514935c8a6dc4822891039311f76b104300348418ffda90cc_amd64 as a component of Red Hat build of Keycloak 22
- rhbk/keycloak-rhel9-operator@sha256:bb21253f5563ba154c9dbd28560443a5d747211232c70645f4aa61f8e3f30bdf_ppc64le as a component of Red Hat build of Keycloak 22
- rhbk/keycloak-rhel9@sha256:7a4e96d7b7b1d25bcc5ce00ea6c5d8d609e9c3368b60972c3995011565ffe5c8_amd64 as a component of Red Hat build of Keycloak 22
- rhbk/keycloak-rhel9@sha256:88f657f1f805ec611ff6ffab89704d86de4affa6cd024be3bd79658561fd544c_ppc64le as a component of Red Hat build of Keycloak 22
- rhbk/keycloak-rhel9@sha256:c2c04c0b330cf4e13b6e22377e20cfed6648bfabaca8d9b30ed0cea730e7b7bf_s390x as a component of Red Hat build of Keycloak 22
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.