RHSA-2024:1867MediumCVSS 8.1

Red Hat Security Advisory: Red Hat build of Keycloak 22.0.10 enhancement and security update

Published
April 16, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2023-0657 — keycloak: impersonation via logout token exchange CVE-2023-3597 — keycloak: secondary factor bypass in step-up authentication CVE-2023-6484 — keycloak: Log Injection during WebAuthn authentication or registration CVE-2023-6544 — keycloak: Authorization Bypass CVE-2023-6717 — keycloak: XSS via assertion consumer service URL in SAML POST-binding flow CVE-2023-6787 — keycloak: session hijacking via re-authentication CVE-2024-1132 — keycloak: path transversal in redirection validation CVE-2024-1249 — keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkLoginIframe leads to DDoS CVE-2024-2419 — keycloak: path traversal in the redirect validation

🎯 Affected products8

  • Red Hat build of Keycloak 22
  • rhbk/keycloak-operator-bundle@sha256:a47cee9b95ed78d7895c2582772abe3ccf239259ee3fbc2d7df8594450dc32f9_amd64 as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:06aa39709dbbd870a14be493bdd452243f700d2910072044ea0d7f8e4abe50b2_amd64 as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:1f5fe6756a3767d1ca8cf3f79c9c14054012f73977602af5c1fc6c5e224fac52_ppc64le as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:be417b344db10adf963d1f64c94e2d214e205489e03395dc508074d783e6422e_s390x as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:20d135d4d422505497c9aa85afb6acb2d9378191358632700e1ce0f259507583_s390x as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:3787bdf294019d8a0f57f7d7e11da98522205de2625c7f287a1d00e11a5b2d83_ppc64le as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:a462539eeff9638d642f13eb2dbc04a47cc39198a7f52d8b6eb07e1e14d783fd_amd64 as a component of Red Hat build of Keycloak 22

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available for this flaw. Workaround: No current mitigation is available for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (12)