Red Hat Single Sign-On 7.4 Update 1 Release Notes

Updated

This software patch resolves a number of security defects and customer reported bugs in Red Hat Single Sign-On 7.4. RH-SSO will deliver patches on a repeating schedule to resolve security defects and customer reported bugs. Fixes for RH-SSO 7.4 will continue until RH-SSO 7.5 is released, and at that time maintenance will be delivered on RH-SSO 7.5.

Updated client adapters are released as needed to resolve customer reported issues or security fixes. The adapters are released as needed so often a given cumulative patch version will not have an associated client adapter for all products.

Red Hat Single Sign-On Server component also includes Red Hat JBoss Enterprise Application Platform and this update includes JBoss Enterprise Application Platform 7.3 Update 1. See the JBoss Enterprise Application Platform 7.3 Update 1 Release Notes for a list of changes included in that release.

Download This content is not included.Red Hat Single Sign-On 7.4 Update 1

Resolved Issues

This update includes fixes for the following security related issues:

IDComponentSummary
CVE-2020-11023Serverjs-jquery: jQuery: passing HTML containing
CVE-2020-10748Servertop-level navigations to data URLs resulting in XSS are possible
CVE-2020-10719Serverundertow: invalid HTTP request with large chunk size
CVE-2020-9548Dependencies - Container, RH-SSOjackson-databind: Serialization gadgets in anteros-core
CVE-2020-9547Dependencies - Container, RH-SSOjackson-databind: Serialization gadgets in ibatis-sqlmap
CVE-2020-9546Dependencies - Container, RH-SSOjackson-databind: Serialization gadgets in shaded-hikari-config
CVE-2020-8840Dependencies - Container, RH-SSOjackson-databind: Lacks certain xbean-reflect/JNDI blocking
CVE-2020-1714RH-SSOLack of checks in ObjectInputStream leading to Remote Code Execution
CVE-2020-1694Adapter - Node.jsverify-token-audience support is missing in the NodeJS adapter

This update includes the following bug fixes or changes:

IDComponentSummary
This content is not included.KEYCLOAK-14411Openshift OperatorUnable to remove keycloak CRs during uninstallation
This content is not included.KEYCLOAK-14353ServerJavaScript injection vulnerability of User registration REST API
This content is not included.KEYCLOAK-14271ServerRe-allow special characters for Roles
This content is not included.KEYCLOAK-14215Servertop-level navigations to data URLs resulting in XSS are possible
This content is not included.KEYCLOAK-14131Server, ThemesCant create client role with configure permission
This content is not included.KEYCLOAK-14080Admin - Console"Resource not found" error thrown when trying to create a policy
This content is not included.KEYCLOAK-14056Admin - Console, Client Registration500 server error when attempting to create an authorization scope for a confidential client
This content is not included.KEYCLOAK-14030Admin - ConsoleMissing RHSSO 7.4 version in MigrationModelManager
This content is not included.KEYCLOAK-13990Admin - Consolefields using kc-password directives are in plain-text
This content is not included.KEYCLOAK-13987ServerDatabase Migration to >=9.0.1 fails on MySQL ???
This content is not included.KEYCLOAK-13917ContainersJAVA_OPTS_APPEND is not taken into consideration in sso74-openshift-rhel8 image
This content is not included.KEYCLOAK-13901Admin - ConsoleCannot create mappers which require certain characters like $
This content is not included.KEYCLOAK-13898Admin - ConsoleCan't add user in admin console when 'Email as username' is enabled
This content is not included.KEYCLOAK-13897Admin - Console, Fine Grained PermissionsClient pagination with reduced permissions results in an empty response
This content is not included.KEYCLOAK-13896New Feature, Adapter - JavascriptAdd support for Application Initiated Actions to keycloak.js
This content is not included.KEYCLOAK-13894Identity BrokeringBetter message when saving a provider with invalid URLs
This content is not included.KEYCLOAK-13893ServerNPE when removing credentials and user cache is disabled
This content is not included.KEYCLOAK-13892Admin - REST API, DatabasePossible Id-replacement issues in the admin REST API and model API
This content is not included.KEYCLOAK-13891Import/ExportNPE importing realm if authenticatorConfig has null alias
This content is not included.KEYCLOAK-13890CoreKeycloak does not perform TLS hostname verification when sending emails via an SMTP server
This content is not included.KEYCLOAK-13888Import/ExportNullPointerException on boot of RHSSO 7.4 or Keycloak 9.0.0 on former Keycloak 8.0.1 installation
This content is not included.KEYCLOAK-13887Adapter - Java Adaptersrefresh token conflicts when "Revoke Refresh Token" is ON
This content is not included.KEYCLOAK-13884Admin - Console, Protocol - SAMLSAML client config: cannot remove fine grain configuration
This content is not included.KEYCLOAK-13882User Federation - LDAP"LOAD_ROLES_BY_MEMBER_ATTRIBUTE_RECURSIVELY" user roles retrieve strategy role-ldap-mapper option should only be displayed if LDAP provider vendor is Active Directory
This content is not included.KEYCLOAK-13881Protocol - SAMLUnsigned SAML logout request throwing invalid_logout_request error
This content is not included.KEYCLOAK-13879Adapter - Java - WildFlyCORS with OIDC requests fails when using elytron adapter
This content is not included.KEYCLOAK-13874Adapter - Java - WildFly, Protocol - SAMLKeycloak Clustered SSO NPE
This content is not included.KEYCLOAK-13871Identity BrokeringIDP review profile allows empty username
This content is not included.KEYCLOAK-13870User Federation - LDAPInconsistency when using "forgot password" after changing email in LDAP
This content is not included.KEYCLOAK-13868Protocol - SAMLUndeclared namespace "ec" while deserializing SAML
This content is not included.KEYCLOAK-13867Identity BrokeringDeleting an Identity Provider doesn't remove the associated IdP Mapper for that user
This content is not included.KEYCLOAK-13866Adapter - Node.jsAdd verify-token-audience support in the NodeJS adapter
This content is not included.KEYCLOAK-13865CoreUsage of ObjectInputStream without checking the object types
This content is not included.KEYCLOAK-13864Admin - Console, Authorization ServicesAuthorization Scope modified improperly when updating Resource
This content is not included.KEYCLOAK-13863AuthenticationDisabling logged in user will not allow other user to login after he is thrown out of his session
This content is not included.KEYCLOAK-13862AuthenticationLogin after registration fails when other user was logged in before
This content is not included.KEYCLOAK-13861User FederationNPE in KeycloakModelUtils.resolveAttribute
This content is not included.KEYCLOAK-13860Identity BrokeringMatch subject when validating id_token returned from external OP
This content is not included.KEYCLOAK-13702Distribution - MavenUpdate 3rd party deps versions automatically in maven repository


Installation

Note: This update should only be applied to zip-based installations.

For instructions on applying Red Hat Single Sign-On cumulative patch (also referred to as a Micro Release) see Micro Upgrades in Red Hat Single Sign-On 7.3 Patching And Upgrading Guide.

The adapters are distributed as a full release which is intended to replace the existing adapter. Full details are available in Upgrading Red Hat Single Sign-On Adapters.

Category
Article Type