RHSA-2021:2965: Moderate: Red Hat Single Sign-On 7.4.8 security update
Red Hat Single Sign-On 7.4 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.This release of Red Hat Single Sign-On 7.4.8 serves as a replacement for Red Hat Single Sign-On 7.4.7, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.Security Fix(es): netty: Request smuggling via content-length header (CVE-2021-21409) wildfly: XSS via admin console when creating roles in domain mode (CVE-2021-3536) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:2965?
The severity of RHSA-2021:2965 is classified as moderate.
How do I fix RHSA-2021:2965?
To fix RHSA-2021:2965, update your Red Hat Single Sign-On to version 7.4.8 or later.
What is affected by RHSA-2021:2965?
RHSA-2021:2965 affects Red Hat Single Sign-On 7.4, specifically version 7.4.7 prior to the fix.
Are there any workarounds for RHSA-2021:2965?
There are no specific workarounds recommended for RHSA-2021:2965; updating is advised.
What types of vulnerabilities does RHSA-2021:2965 address?
RHSA-2021:2965 addresses vulnerabilities related to authentication and security standards in Red Hat Single Sign-On.