RHSA-2024:6889HighCVSS 7.7
Red Hat Security Advisory: Red Hat build of Keycloak 24.0.8 Images Update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-8698 — keycloak-saml-core: Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak CVE-2024-8883 — Keycloak: Vulnerable Redirect URI Validation Results in Open Redirec
🎯 Affected products8
- Red Hat build of Keycloak 24
- rhbk/keycloak-operator-bundle@sha256:5a8c89df8070d7ac5162ecfe625571fdfce8fa9ef5dc3e3c4a54b1c6a54e5894_amd64 as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9-operator@sha256:4be3b36ff7d231692defc0db16d1b90bd8bb39052299a767f76153507c084140_amd64 as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9-operator@sha256:60e6aecbd316fdb305039b68f78e5160c2928fdd7288f49c3a70897421962ca6_ppc64le as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9-operator@sha256:da701bfd33e241333482073822ee5ff75a16a400b1bd6459a1150e2ab39eb31b_s390x as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9@sha256:67d24b569e457843ed28a0ecc49273f463ddf8906b2874e724419baa195a8f23_ppc64le as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9@sha256:725159f29d13741b6af8b346a922286f78af42e97a687eab906b38dc795be1dd_s390x as a component of Red Hat build of Keycloak 24
- rhbk/keycloak-rhel9@sha256:bbfde12778000483ebc145da4bbc0720bbbbb66dd21fdf34ce57d9b3f293c910_amd64 as a component of Red Hat build of Keycloak 24
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:6889
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311641
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312511
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6889.json