Red Hat Single Sign-On 7.6 Update 8 Release Notes

Updated

This software patch resolves a number of security defects and customer reported bugs in Red Hat Single Sign-On 7.6. RH-SSO will deliver patches on a repeating schedule to resolve security defects and customer reported bugs. Fixes for RH-SSO 7.6 will continue until RH-SSO 7.6 is end of life.

Updated client adapters are released as needed to resolve customer reported issues or security fixes. The adapters are released as needed so often a given cumulative patch version will not have an associated client adapter for all products.

Red Hat Single Sign-On Server component also includes Red Hat JBoss Enterprise Application Platform and this update includes JBoss Enterprise Application Platform 7.4 Update 15. See the JBoss Enterprise Application Platform 7.4 Update 15 Release Notes for a list of changes included in that release.

Download This content is not included.Red Hat Single Sign-On 7.6 Update 8

Resolved Issues

This update includes fixes for the following security related issues:

IDSummary
CVE-2024-1132keycloak: path transversal in redirection validation
CVE-2024-1249keycloak OIDC: unvalidated cross-origin messages in checkLoginIframe leads to DDoS
CVE-2023-6544keycloak-core: Authorization Bypass
CVE-2023-6484keycloak Operator: Log Injection during WebAuthn authentication or registration
CVE-2023-3597keycloak : secondary factor bypass in step-up authentication

This update includes the following bug fixes or changes:

IDComponentSummary
This content is not included.RHSSO-2298ServerIncorrect HTTP status reported when DNS resolver is not available
This content is not included.RHSSO-2519ServerReset password flow fails with "Page has expired" error when Kerberos authentication is enabled in the browser flow
This content is not included.RHSSO-2592ServerSupport Java 17
This content is not included.RHSSO-2598OperatorRH-SSO Operator occasionally creates an Ingress resource on OpenShift
This content is not included.RHSSO-2807ServerInconsistent behaviour on getting user permissions using authorization
This content is not included.RHSSO-2857ServerScript for automatic heap size calculation is broken in OpenShift 4.14
This content is not included.RHSSO-2934OperatorThrottling request took in RH-SSO Operator
This content is not included.RHSSO-2940ServerBackport mitigations for phase-out of 3rd party cookies to RH-SSO

Installation

Note: This update should only be applied to zip-based installations.

For instructions on applying Red Hat Single Sign-On cumulative patch (also referred to as a Micro Release) see Micro Upgrades in Red Hat Single Sign-On 7.6 Patching And Upgrading Guide.

The adapters are distributed as a full release which is intended to replace the existing adapter. Full details are available in Upgrading Red Hat Single Sign-On Adapters.

Category
Components
Article Type