[RHSA-2022:8962-01] Important: Red Hat Single Sign-On 7.6.1 security update on RHEL 8

Security announcements for all Red Hat products and services. rhsa-announce at redhat.com
Tue Dec 13 16:34:29 UTC 2022


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: Red Hat Single Sign-On 7.6.1 security update on RHEL 8
Advisory ID:       RHSA-2022:8962-01
Product:           Red Hat Single Sign-On
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:8962
Issue date:        2022-12-13
CVE Names:         CVE-2022-3782 CVE-2022-3916 
=====================================================================

1. Summary:

New Red Hat Single Sign-On 7.6.1 packages are now available for Red Hat
Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Single Sign-On 7.6 for RHEL 8 - noarch

3. Description:

Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak
project, that provides authentication and standards-based single sign-on
capabilities for web and mobile applications.

This release of Red Hat Single Sign-On 7.6.1 on RHEL 8 serves as a
replacement for Red Hat Single Sign-On 7.6.1, and includes the security
fixes listed below.

Security Fix(es):

* keycloak: path traversal via double URL encoding (CVE-2022-3782)

* keycloak: Session takeover with OIDC offline refreshtokens
(CVE-2022-3916)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

2138971 - CVE-2022-3782 keycloak: path traversal via double URL encoding
2141404 - CVE-2022-3916 keycloak: Session takeover with OIDC offline refreshtokens

6. JIRA issues fixed (https://issues.jboss.org/):

CIAM-4414 - Build RPMs for this patch

7. Package List:

Red Hat Single Sign-On 7.6 for RHEL 8:

Source:
rh-sso7-keycloak-18.0.3-1.redhat_00002.1.el8sso.src.rpm

noarch:
rh-sso7-keycloak-18.0.3-1.redhat_00002.1.el8sso.noarch.rpm
rh-sso7-keycloak-server-18.0.3-1.redhat_00002.1.el8sso.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

8. References:

https://access.redhat.com/security/cve/CVE-2022-3782
https://access.redhat.com/security/cve/CVE-2022-3916
https://access.redhat.com/security/updates/classification/#important

9. Contact:

The Red Hat security contact is <secalert at redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBY5ipldzjgjWX9erEAQiTxQ//X1uZTMfjqFKgWwdGQx+411ANW503To42
itxaBWhSxJmbzOhJB0QKoABPCapl3mwrPC+XfdGL2sorqFFjbXNa6TkaQecfVqt2
qwTqtEix3WQVmK2PY9e//9sea/vwfwBOfhqxgiML3ZMzrfXHzIgnWNSPE5eYT+n9
riKkquCR7kInls3lkxgpKEQjsJXyR1FhIGzS4J8tmgHsG46zOF4fYsPI2BVj6VJg
Y55XjFXoPjZdKWzdHNVBzuRIuoCBEToZHPNzA4D387FsAPSqVwrEQ5S0VUL7bJ/t
WY03oVmytyvgwUnwzUSy1qgFDpzY68YAtCLdO2sNPqybiFUKAWevhCNK8Dksf7VM
zUpmIZF5EtKAQZIF1LH+DTtwWJr+Uvy/vnbA+CqwwUcQv6/mKQIBLsIHMaLyB3Bu
3KSksEllW6XQ+c1JFQ1BmDdkyHhmRYXxxkGqxmtW7cFj4K+rnWqu+o7IRJvbXUJM
F3ryJcFk/0tYmzHUqCgQZQvJQwF5QCVZdIMZrAAI6ugGE5m2VeSJBgb+aHNIwn9/
Ji9OdKRuzPJFjmuZy67RaFbF37ILTeQB6uVPz0PLjcjJZAP/NN5CjWbTS/D7Q0J/
RgIZe5uv4sYOkH0+jd6CYQp7GVXlPvT/uVE3eONol+FgT5lyf6fWZE2vjQQsO/26
ZyVkdE4wcmo=
=CFoY
-----END PGP SIGNATURE-----


More information about the RHSA-announce mailing list