RHSA-2024:6502MediumCVSS 7.1

Red Hat Security Advisory: Red Hat build of Keycloak 24.0.7 Images Update

Published
September 9, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-7260 — keycloak-core: Open Redirect on Account page CVE-2024-7318 — keycloak-core: One Time Passcode (OTP) is valid longer than expiration timeSeverity CVE-2024-7341 — wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters

🎯 Affected products8

  • Red Hat build of Keycloak 24
  • rhbk/keycloak-operator-bundle@sha256:c8d17b07c4e84a514529674d019668e003f85a672f30213ba9320aa81f64d010_amd64 as a component of Red Hat build of Keycloak 24
  • rhbk/keycloak-rhel9-operator@sha256:0b6f71aa1735670a881e0c9fd6c95851f077fb204e004beffc8481d7220ae095_s390x as a component of Red Hat build of Keycloak 24
  • rhbk/keycloak-rhel9-operator@sha256:201b5716a28a2d31338a75e844259f278612354010c6c3ac1ccfb60bd194df29_amd64 as a component of Red Hat build of Keycloak 24
  • rhbk/keycloak-rhel9-operator@sha256:b46a8d3105bf1e3a31ca707b032223b38cf3381a57f7f44a150f399b68115346_ppc64le as a component of Red Hat build of Keycloak 24
  • rhbk/keycloak-rhel9@sha256:00a713fd08f68df2e3b06c9131eb732febb70e795e0345e7a5df1d1fb8ac45b4_amd64 as a component of Red Hat build of Keycloak 24
  • rhbk/keycloak-rhel9@sha256:71ca272bd39f0b082758f0c82df1302d9b51a5b445010944f734242bbe2eefb6_ppc64le as a component of Red Hat build of Keycloak 24
  • rhbk/keycloak-rhel9@sha256:991795cc7cdb6a2ccc55c935a34291a01a9784be306ec980eb3904d64466629e_s390x as a component of Red Hat build of Keycloak 24

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (6)