RHSA-2024:10177HighCVSS 7.1
Red Hat Security Advisory: Red Hat build of Keycloak 26.0.6 Images Update
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-9666 — org.keycloak/keycloak-quarkus-server: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability CVE-2024-10039 — keycloak-core: mTLS passthrough CVE-2024-10270 — org.keycloak:keycloak-services: Keycloak Denial of Service CVE-2024-10451 — org.keycloak:keycloak-quarkus-server: Sensitive Data Exposure in Keycloak Build Process CVE-2024-10492 — keycloak-quarkus-server: Keycloak path trasversal
🎯 Affected products8
- Red Hat build of Keycloak 26.0
- rhbk/keycloak-operator-bundle@sha256:df1759af072286178f29d7b70cb44cacf29698449b5aaf7284b7eaf3086ae7a7_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:89607e68cfdc0741090e4fbec8e253c60fc1fc7748504ec965bdfd71a556de68_s390x as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:9d5a5d7a2caadab9479b3c76c1a58a4706335317aa140c56f2444131aaa75fec_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:f42eac86465f8c2cd7c9e8d5be2f5efb0d3aa78edb065c3c7df99c89c865f07c_ppc64le as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:6660b8b5c6628e835d01fbe7a464120d147d5b571cc5916afe800b2eb2b6d3d5_s390x as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:9f0c7ff5d4f97775801fcc17392eaba634eceb8407b0635998a406cf784591cb_ppc64le as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:b3cf32eb519b285c4796a9ee110e323fc58beb5780fc7ddec2467da54717b216_amd64 as a component of Red Hat build of Keycloak 26.0
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:10177
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2319217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2321214
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2322096
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2322447
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10177.json