RHSA-2024:6500MediumCVSS 7.1

Red Hat Security Advisory: Red Hat build of Keycloak 22.0.12 Images Update

Published
September 9, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-4629 — keycloak: potential bypass of brute force protection CVE-2024-5967 — keycloak: Leak of configured LDAP bind credentials through the Keycloak admin console CVE-2024-7341 — wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters

🎯 Affected products8

  • Red Hat build of Keycloak 22
  • rhbk/keycloak-operator-bundle@sha256:43fc6282df4d91c68a9618f9bf2a4159690e69c207b8ba60e907dd64847fdc53_amd64 as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:29626722accc2d089262f4ef101819a46b4ea608e1865fd59ea5ac3b3661e9ec_s390x as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:73e1d687a59f2adff13c64109c9f7da91e340c73eae673905360bf86925820e8_amd64 as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:a5bdad714236fe8b179215915b1cb466fe5b0c3d5da1cfe0debd8c963084f4bb_ppc64le as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:4997cbb3b782b64e7b4c14d2cd0ac6cc98aa8d76bd538ccf46f48493fcf30837_ppc64le as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:6fd26b6c895ab17f670e119376a956400fe35b2b3ea99a07a5fa4dd08cb8eb95_amd64 as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:cdfa1a0a652fbbb8291afe1db95bc30bd39a2f2e5fbc085825b56c51bdc78748_s390x as a component of Red Hat build of Keycloak 22

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (6)