RHSA-2024:10175HighCVSS 7.1
Red Hat Security Advisory: Red Hat build of Keycloak 24.0.9 Images Update
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-9666 — org.keycloak/keycloak-quarkus-server: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability CVE-2024-10039 — keycloak-core: mTLS passthrough CVE-2024-10270 — org.keycloak:keycloak-services: Keycloak Denial of Service CVE-2024-10451 — org.keycloak:keycloak-quarkus-server: Sensitive Data Exposure in Keycloak Build Process CVE-2024-10492 — keycloak-quarkus-server: Keycloak path trasversal
🎯 Affected products8
- Red Hat build of Keycloak 24
- rhbk/keycloak-operator-bundle@sha256:b88294b9033853bf4874fe5f14757c217c7ab3901dfd6ded46b880fd9bd9543b_amd64 as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9-operator@sha256:3c74dc71609ff709e4221145dbca43ea1fd973789d3b380a00402e7700d10b68_amd64 as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9-operator@sha256:446294f7b35b9e1a3ad908ceab53fabbd1b8dfa0535e6b9a7acebcd038a2507a_ppc64le as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9-operator@sha256:b0259432bac5499e7ea08136ef8357851d1f5be64a3b5086cdf46bfaac9d50b0_s390x as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9@sha256:0d281d30fa7f931cabd50b24c908c2b61c1fc527326626ad4fff548e47bfd577_ppc64le as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9@sha256:69f6df6ec90aca5d801c6724e5350700548d8903a4be3aef7a1bb95bbbbdb0c6_amd64 as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9@sha256:801d2ade5b61cadf0508f347881ae496e679725a6052653619044a63938b8184_s390x as a component of Red Hat build of Keycloak 24
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:10175
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2319217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2321214
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2322096
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2322447
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10175.json