Issued:
2024-04-16
Updated:
2024-04-16

RHSA-2024:1865 - Low: Red Hat Single Sign-On 7.6.8 Operator enhancement and security update


Synopsis

Low: Red Hat Single Sign-On 7.6.8 Operator enhancement and security update

Type/Severity

Security Advisory Low

Topic

Red Hat Single Sign-On 7.6.8 Operator enhancement and security update.

This is an enhancement and security update with Low impact rating and package name 'rh-sso7-keycloak'. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat Single Sign-On 7.6.8 Operator for OpenShift simplifies deployment and management of Single-Sign-On 7.6.8 clusters. The Operator is supported on Red Hat OpenShift Container Platform 4.9.

Security Fix(es):

  • Log Injection during WebAuthn authentication or registration (CVE-2023-6484)

Solution

To install the Red Hat Single Sign-On Operator, use the Operator Marketplace interface in OpenShift Container Platform.

Affected Products

ProductVersionArch
Red Hat OpenShift Container Platform4.12x86_64
Red Hat OpenShift Container Platform4.11x86_64
Red Hat OpenShift Container Platform for Power4.9ppc64le
Red Hat OpenShift Container Platform for Power4.10ppc64le
Red Hat OpenShift Container Platform for IBM Z and LinuxONE4.9s390x
Red Hat OpenShift Container Platform for IBM Z and LinuxONE4.10s390x

Fixes

CVEs

References


Additional information