RHSA-2024:0801HighCVSS 7.1

Red Hat Security Advisory: Red Hat Single Sign-On 7.6.7 for OpenShift image enhancement update

Published
February 13, 2024
Last Modified
August 19, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2023-2976 — guava: insecure temporary directory creation CVE-2023-6134 — keycloak: reflected XSS via wildcard in OIDC redirect_uri CVE-2023-6291 — keycloak: redirect_uri validation bypass CVE-2023-6484 — keycloak: Log Injection during WebAuthn authentication or registration CVE-2023-6927 — keycloak: open redirect via "form_post.jwt" JARM response mode CVE-2023-26048 — jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() CVE-2023-26049 — jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies CVE-2023-44483 — santuario: Private Key disclosure in debug-log output

🎯 Affected products4

  • Middleware Containers for OpenShift
  • rh-sso-7/sso76-openshift-rhel8@sha256:1cde6dbbee3aa25be767953c45670d4c2592d61a7af776e7e0d0d1b08a1d23ab_amd64 as a component of Middleware Containers for OpenShift
  • rh-sso-7/sso76-openshift-rhel8@sha256:23d03851f0946e0ce058bfeeb458112e752b6b0dd8ebca078dc41b8e94c8e995_s390x as a component of Middleware Containers for OpenShift
  • rh-sso-7/sso76-openshift-rhel8@sha256:2a21973655961ae87984bf1b76843419680fb0228fa0084c5bf8c696058bbc8d_ppc64le as a component of Middleware Containers for OpenShift

✅ Remediation

To update to the latest Red Hat Single Sign-On 7.6.7 for OpenShift image, Follow these steps to pull in the content: 1. On your main hosts, ensure you are logged into the CLI as a cluster administrator or user with project administrator access to the global "openshift" project. For example: $ oc login -u system:admin 2. Update the core set of Red Hat Single Sign-On resources for OpenShift in the "openshift" project by running the following commands: $ for resource in sso76-image-stream.json \ sso76-https.json \ sso76-mysql.json \ sso76-mysql-persistent.json \ sso76-postgresql.json \ sso76-postgresql-persistent.json \ sso76-x509-https.json \ sso76-x509-mysql-persistent.json \ sso76-x509-postgresql-persistent.json do oc replace -n openshift --force -f \ https://raw.githubusercontent.com/jboss-container-images/redhat-sso-7-openshift-image/v7.6.7.GA/templates/${resource} done 3. Install the Red Hat Single Sign-On 7.6.7 for OpenShift streams in the "openshift" project by running the following commands: $ oc -n openshift import-image redhat-sso76-openshift:1.0 Workaround: Temp files should be created with sufficiently non-predictable names and in a secure-permissioned, dedicated temp folder. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (11)