RHSA-2024:6887HighCVSS 7.7

Red Hat Security Advisory: Red Hat build of Keycloak 22.0.13 Images Update

Published
September 19, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-8698 — keycloak-saml-core: Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak CVE-2024-8883 — Keycloak: Vulnerable Redirect URI Validation Results in Open Redirec

🎯 Affected products8

  • Red Hat build of Keycloak 22
  • rhbk/keycloak-operator-bundle@sha256:c342da2a8183de278abebf98ef23332ce382544233a8b1128bf1ff74126e9c14_amd64 as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:8239d0783acc13b77f810aa2a7b7419a2ce35b0f0df32a7d0e9ef94150109b54_s390x as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:a8d1dad5b4093ea07cda030ee119005d613af15cdd7d483e5ccd668fe71838aa_amd64 as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:dcfb4b320526118e5ce3e7d448f85d1bf76a38b4af10425c99b30f5fdb89aa4c_ppc64le as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:14d6a02500b27314cd7b6963b296b5a459aaf96b395f15f53a2428f318e7a53a_ppc64le as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:68b30f30ebe5132a445e94291bea01836d68cdb06a51e5c358843e137e630028_s390x as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:b89ec71d15ad9a3954006bc8b61ece2973ac0d1d725c49e949c2ae16f0fb8489_amd64 as a component of Red Hat build of Keycloak 22

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)