RHSA-2024:10177HighCVSS 7.1

Red Hat Security Advisory: Red Hat build of Keycloak 26.0.6 Images Update

Published
November 21, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2024-9666 — org.keycloak/keycloak-quarkus-server: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability CVE-2024-10039 — keycloak-core: mTLS passthrough CVE-2024-10270 — org.keycloak:keycloak-services: Keycloak Denial of Service CVE-2024-10451 — org.keycloak:keycloak-quarkus-server: Sensitive Data Exposure in Keycloak Build Process CVE-2024-10492 — keycloak-quarkus-server: Keycloak path trasversal

🎯 Affected products8

  • Red Hat build of Keycloak 26.0
  • rhbk/keycloak-operator-bundle@sha256:df1759af072286178f29d7b70cb44cacf29698449b5aaf7284b7eaf3086ae7a7_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:89607e68cfdc0741090e4fbec8e253c60fc1fc7748504ec965bdfd71a556de68_s390x as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:9d5a5d7a2caadab9479b3c76c1a58a4706335317aa140c56f2444131aaa75fec_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:f42eac86465f8c2cd7c9e8d5be2f5efb0d3aa78edb065c3c7df99c89c865f07c_ppc64le as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:6660b8b5c6628e835d01fbe7a464120d147d5b571cc5916afe800b2eb2b6d3d5_s390x as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:9f0c7ff5d4f97775801fcc17392eaba634eceb8407b0635998a406cf784591cb_ppc64le as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:b3cf32eb519b285c4796a9ee110e323fc58beb5780fc7ddec2467da54717b216_amd64 as a component of Red Hat build of Keycloak 26.0

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (8)