RHSA-2024:10176HighCVSS 7.1
Red Hat Security Advisory: Red Hat build of Keycloak 24.0.9 Update
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-9666 — org.keycloak/keycloak-quarkus-server: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability CVE-2024-10039 — keycloak-core: mTLS passthrough CVE-2024-10270 — org.keycloak:keycloak-services: Keycloak Denial of Service CVE-2024-10451 — org.keycloak:keycloak-quarkus-server: Sensitive Data Exposure in Keycloak Build Process CVE-2024-10492 — keycloak-quarkus-server: Keycloak path trasversal
🎯 Affected products1
- Red Hat build of Keycloak 24.0.9
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:10176
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2319217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2321214
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2322096
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2322447
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10176.json