RHSA-2022:0409: Important: Red Hat Single Sign-On 7.4.10 on OpenJDK for OpenShift image security update
Red Hat Single Sign-On is an integrated sign-on solution, available as a<br>Red Hat JBoss Middleware for OpenShift containerized image. The Red Hat<br>Single Sign-On for OpenShift image provides an authentication server that<br>you can use to log in centrally, log out, and register. You can also manage<br>user accounts for web applications, mobile applications, and RESTful web<br>services.<br>This erratum releases a new image for Red Hat Single Sign-On 7.4.10 for<br>use within the OpenShift Container Platform 3.10, OpenShift Container Platform<br>3.11, and within the OpenShift Container Platform 4.3 cloud computing Platform-as-a-Service (PaaS) for<br>on-premise or private cloud deployments, aligning with the standalone product release.<br>Security Fix(es):<br><li> undertow: client side invocation timeout raised when calling over HTTP and</li> HTTP2 (CVE-2021-3859)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, and other related information, refer to the CVE page(s) listed in the<br>References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0409?
The severity of RHSA-2022:0409 is classified as important.
How do I fix RHSA-2022:0409?
To fix RHSA-2022:0409, you should apply the latest updates available for Red Hat Single Sign-On and Red Hat OpenShift Container Platform.
What products are affected by RHSA-2022:0409?
RHSA-2022:0409 affects Red Hat Single Sign-On and versions of Red Hat OpenShift Container Platform from 3.10 to 4.3.
Is RHSA-2022:0409 a critical vulnerability?
No, RHSA-2022:0409 has been classified with an important severity, not critical.
What types of issues does RHSA-2022:0409 address?
RHSA-2022:0409 addresses security vulnerabilities related to authentication and session management in affected products.