RHSA-2023:1049: Important: Red Hat Single Sign-On 7.6.2 security update
Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.This release of Red Hat Single Sign-On 7.6.2 serves as a replacement for Red Hat Single Sign-On 7.6.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.Security Fix(es): keycloak: XSS on impersonation under specific circumstances (CVE-2022-1438) Moment.js: Path traversal in moment.locale (CVE-2022-24785) keycloak: missing email notification template allowlist (CVE-2022-1274) keycloak: minimist: prototype pollution (CVE-2021-44906) moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129) undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations (CVE-2022-2764) snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857) loader-utils: loader-utils:Regular expression denial of service (CVE-2022-37603) keycloak: Session takeover with OIDC offline refreshtokens (CVE-2022-3916) keycloak: path traversal via double URL encoding (CVE-2022-3782) snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode (CVE-2022-38749) snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match (CVE-2022-38751) snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject (CVE-2022-38750) keycloak: Client Registration endpoint does not check token revocation (CVE-2023-0091) keycloak: glob-parent: Regular Expression Denial of Service (CVE-2021-35065) json5: Prototype Pollution in JSON5 via Parse Method (CVE-2022-46175) keycloak: keycloak: user impersonation via stolen uuid code (CVE-2023-0264) snakeyaml: Constructor Deserialization Remote Code Execution (CVE-2022-1471) CXF: Apache CXF: SSRF Vulnerability (CVE-2022-46364) rcue-bootstrap: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip (CVE-2018-14042) jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos (CVE-2022-45693) sshd-common: mina-sshd: Java unsafe deserialization vulnerability (CVE-2022-45047) jettison: memory exhaustion via user-supplied XML or JSON data (CVE-2022-40150) jettison: parser crash by stackoverflow (CVE-2022-40149) jackson-databind: use of deeply nested arrays (CVE-2022-42004) jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS (CVE-2022-42003) jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022) bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040) jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358) CXF: Apache CXF: directory listing / code exfiltration (CVE-2022-46363) keycloak: reflected XSS attack (CVE-2022-4137) Keycloak Node.js Adapter: Open redirect vulnerability in checkSSO (CVE-2022-2237) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1049?
The severity of RHSA-2023:1049 is classified as critical.
What products are affected by RHSA-2023:1049?
RHSA-2023:1049 impacts Red Hat Single Sign-On 7.6.2 and related components.
How do I fix RHSA-2023:1049?
To address RHSA-2023:1049, you should upgrade to the latest version of Red Hat Single Sign-On 7.6.2.
What vulnerabilities are addressed in RHSA-2023:1049?
RHSA-2023:1049 resolves multiple security flaws that could lead to unauthorized access.
When was RHSA-2023:1049 released?
RHSA-2023:1049 was released on March 15, 2023.