Red Hat Security Advisory: Red Hat Single Sign-On 7.6.8 for OpenShift image enhancement and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-6484 — keycloak: Log Injection during WebAuthn authentication or registration CVE-2023-6544 — keycloak: Authorization Bypass CVE-2024-1132 — keycloak: path transversal in redirection validation CVE-2024-1249 — keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkLoginIframe leads to DDoS CVE-2024-1635 — undertow: Out-of-memory Error after several closed connections with wildfly-http-client protocol
🎯 Affected products4
- Middleware Containers for OpenShift
- rh-sso-7/sso76-openshift-rhel8@sha256:1909db8bc47fdb4f6512e08fb21ec1457f64fa0abf8edf2530f5bf5a494d9b6d_amd64 as a component of Middleware Containers for OpenShift
- rh-sso-7/sso76-openshift-rhel8@sha256:1f842e8f262ece6cd98941fd29562251e19479eb4f4ba7cbd8e9a3bfa79325f0_s390x as a component of Middleware Containers for OpenShift
- rh-sso-7/sso76-openshift-rhel8@sha256:b666f093f22ef27811114cca95c20aed890d4f3342116ab990d084cb2627d8cf_ppc64le as a component of Middleware Containers for OpenShift
✅ Remediation
To update to the latest Red Hat Single Sign-On 7.6.8 for OpenShift image, Follow these steps to pull in the content: 1. On your main hosts, ensure you are logged into the CLI as a cluster administrator or user with project administrator access to the global "openshift" project. For example: $ oc login -u system:admin 2. Update the core set of Red Hat Single Sign-On resources for OpenShift in the "openshift" project by running the following commands: $ for resource in sso76-image-stream.json \ sso76-https.json \ sso76-mysql.json \ sso76-mysql-persistent.json \ sso76-postgresql.json \ sso76-postgresql-persistent.json \ sso76-x509-https.json \ sso76-x509-mysql-persistent.json \ sso76-x509-postgresql-persistent.json do oc replace -n openshift --force -f \ https://raw.githubusercontent.com/jboss-container-images/redhat-sso-7-openshift-image/v7.6.8.GA/templates/${resource} done 3. Install the Red Hat Single Sign-On 7.6.8 for OpenShift streams in the "openshift" project by running the following commands: $ oc -n openshift import-image redhat-sso76-openshift:1.0 Workaround: No mitigation is currently available for this flaw. Workaround: No current mitigation is available for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is currently available for this vulnerability. However, there might be some protections, such as request limits by a load balancer in front of JBoss EAP/Wildfly or even Undertow, that could minimize the impact.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:1864
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2248423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253116
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262117
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262918
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264928
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1864.json