- Issued:
- 2025-07-23
- Updated:
- 2025-07-23
RHSA-2025:11645 - Security Advisory
Synopsis
Moderate: Red Hat Single Sign-On 7.6.12 security update
Type/Severity
Security Advisory: Moderate
Topic
A new security update is now available for Red Hat Single Sign-On 7.6 from the Customer Portal.
Description
Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.
This release of Red Hat Single Sign-On 7.6.12 serves as a replacement for Red Hat Single Sign-On 7.6.11, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. This security update has moderate impact.
Security fixes:
- org.wildfly.core/wildfly-core-management-client: Wildfly vulnerable to Cross-Site Scripting (XSS) (CVE-2024-10234)
Solution
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
The References section of this erratum contains a download link (you must log in to download the update).
Affected Products
- Red Hat Single Sign-On Text-Only Advisories x86_64
Fixes
- BZ - 2320848 - CVE-2024-10234 wildfly: Wildfly vulnerable to Cross-Site Scripting (XSS)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.