Red Hat Security Advisory: Red Hat build of Keycloak security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2023-0657 — keycloak: impersonation via logout token exchange CVE-2023-3597 — keycloak: secondary factor bypass in step-up authentication CVE-2023-6484 — keycloak: Log Injection during WebAuthn authentication or registration CVE-2023-6544 — keycloak: Authorization Bypass CVE-2023-6717 — keycloak: XSS via assertion consumer service URL in SAML POST-binding flow CVE-2023-6787 — keycloak: session hijacking via re-authentication CVE-2024-1132 — keycloak: path transversal in redirection validation CVE-2024-1249 — keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkLoginIframe leads to DDoS
🎯 Affected products1
- Red Hat build of Keycloak 22.0.10
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available for this flaw. Workaround: No current mitigation is available for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2024:1868
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2166728
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221760
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2248423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253116
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253952
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254375
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262117
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262918
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1868.json