- Issued:
- 2024-04-16
- Updated:
- 2024-04-16
RHSA-2024:1865 - Security Advisory
Synopsis
Low: Red Hat Single Sign-On 7.6.8 Operator enhancement and security update
Type/Severity
Security Advisory: Low
Topic
Red Hat Single Sign-On 7.6.8 Operator enhancement and security update.
This is an enhancement and security update with Low impact rating and
package name 'rh-sso7-keycloak'. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available for each
vulnerability from the CVE link(s) in the References section.
Description
Red Hat Single Sign-On 7.6.8 Operator for OpenShift
simplifies deployment and management of Single-Sign-On 7.6.8 clusters. The
Operator is supported on Red Hat OpenShift Container Platform 4.9.
Security Fix(es):
- Log Injection during WebAuthn authentication or registration (CVE-2023-6484)
Solution
To install the Red Hat Single Sign-On Operator, use the Operator Marketplace
interface in OpenShift Container Platform.
Affected Products
- Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
- Red Hat OpenShift Container Platform for Power 4.9 for RHEL 8 ppc64le
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.9 for RHEL 8 s390x
Fixes
- BZ - 2248423 - CVE-2023-6484 keycloak: Log Injection during WebAuthn authentication or registration
ppc64le
rh-sso-7/sso7-rhel8-init-container@sha256:f02e961e0c796ac8b65de30a5c364c63337003ba9d2b05b7041565cf3bd9d8c0 |
rh-sso-7/sso7-rhel8-operator@sha256:990daa5745e5c3ba9da0087a0198de272027794949b8c5f45b86023702bfe8a0 |
s390x
rh-sso-7/sso7-rhel8-init-container@sha256:d89710eaa9b45dc180c311bd020255759383b0eb07826265e4ba810c6a047196 |
rh-sso-7/sso7-rhel8-operator@sha256:586edd67e9b88b7f11bcec01308ef66aa20f7fd7307b821c1e6da5dbdee0786a |
x86_64
rh-sso-7/sso7-rhel8-init-container@sha256:7c11cf4ea78020a3fba69c85e56c1c1eed08af61e7215dae5dcf7425f341b79d |
rh-sso-7/sso7-rhel8-operator@sha256:bc38682492e8166dca7a08d0eae81469270b5f979ff80f075bc63183126098c0 |
rh-sso-7/sso7-rhel8-operator-bundle@sha256:81208c494048b526ff577b0c9673f4e310e84627671d2da7ac072aa11292aedc |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.