Red Hat Single Sign-On 7.4 Update 6 Release Notes

Updated

This software patch resolves a number of security defects and customer reported bugs in Red Hat Single Sign-On 7.4. RH-SSO will deliver patches on a repeating schedule to resolve security defects and customer reported bugs. Fixes for RH-SSO 7.4 will continue until RH-SSO 7.5 is released, and at that time maintenance will be delivered on RH-SSO 7.5.

Updated client adapters are released as needed to resolve customer reported issues or security fixes. The adapters are released as needed so often a given cumulative patch version will not have an associated client adapter for all products.

Red Hat Single Sign-On Server component also includes Red Hat JBoss Enterprise Application Platform and this update includes JBoss Enterprise Application Platform 7.3 Update 6. See the JBoss Enterprise Application Platform 7.3 Update 6 Release Notes for a list of changes included in that release.

Download This content is not included.Red Hat Single Sign-On 7.4 Update 6

Important Notices

Red Hat Single Sign-On is deprecated Internet Explorer testing as a tested integration. Testing for Internet Explorer will be discontinued and replaced with Microsoft Edge in the next release.

Resolved Issues

This update includes fixes for the following security related issues:

IDComponentSummary
CVE-2020-7676NodeJS Adapterangular: nodejs-angular: XSS due to regex-based HTML replacement
CVE-2020-14302Serverkeycloak: reusable "state" parameter at redirect_uri endpoint enables possibility of replay attacks
CVE-2021-20250Serverjboss-ejb-client: wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client
CVE-2021-20220Serverwildfly-undertow: undertow: Possible regression in fix for CVE-2020-10687
CVE-2020-28052Serverbouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible
CVE-2020-35510Serverjboss-remoting: Threads hold up forever in the EJB server by suppressing the ack from an EJB client
CVE-2020-8908Serverguava: local information disclosure via temporary directory created with unsafe permissions

This update includes the following bug fixes or changes:

IDComponentSummary
This content is not included.KEYCLOAK-17249Container - OperatorThe RHSSO metrics endpoint is exposed to the outside world - OCP Route
This content is not included.KEYCLOAK-17207Server, Admin - REST APIAvoid removing attributes when updating user and profile
This content is not included.KEYCLOAK-17151Admin - REST APIREST API call PUT /{realm}/users/{id} rejects selective/partial user representation updates
This content is not included.KEYCLOAK-17150Account - REST APIUpdating user account removes attributes
This content is not included.KEYCLOAK-17130Account - ConsoleUser attributes are lost after user updates account with Account Management Console
This content is not included.KEYCLOAK-16940Authorization ServicesAuthz client still relying on refresh tokens when doing client credentials
This content is not included.KEYCLOAK-16736ContainerWORKDIR is missed in the latest rh-sso-7/sso74-openshift-rhel8 container
This content is not included.KEYCLOAK-16618Container - OperatorSupport StorageClass for Postgres DB via CR
This content is not included.KEYCLOAK-16599Container - Operator, RH-SSORegenerate CRDs as part of the build pipeline
This content is not included.KEYCLOAK-15239Authentication, RH-SSOReset Password Success Message not shown when Kerberos is Enabled
This content is not included.KEYCLOAK-17332Adapter - SpringUpgrade Spring Boot 2.3 and Jetty 9.4
This content is not included.KEYCLOAK-17271Container - OperatorRestructure the monitoring stack
This content is not included.KEYCLOAK-17246Container - OperatorUse at least two owners for caches in RHSSO image - operator change
This content is not included.KEYCLOAK-17220Container - OperatorAdd anti-affinity settings to Keycloak Pods


Installation

Note: This update should only be applied to zip-based installations.

For instructions on applying Red Hat Single Sign-On cumulative patch (also referred to as a Micro Release) see Micro Upgrades in Red Hat Single Sign-On 7.4 Patching And Upgrading Guide.

The adapters are distributed as a full release which is intended to replace the existing adapter. Full details are available in Upgrading Red Hat Single Sign-On Adapters.

Category
Components
Article Type