drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in Red Hat build of Keycloak 26.0.8
| Name: |
Zwei Probleme in Red Hat build of Keycloak 26.0.8 |
|
| ID: |
RHSA-2025:0300 |
|
| Distribution: |
Red Hat |
|
| Plattformen: |
Red Hat RHBK 26.0.8 |
|
| Datum: |
Mi, 15. Januar 2025, 06:34 |
|
| Referenzen: |
https://bugzilla.redhat.com/show_bug.cgi?id=2328850
https://access.redhat.com/security/cve/CVE-2024-11736
https://access.redhat.com/errata/RHSA-2025:0300
https://access.redhat.com/security/cve/CVE-2024-11734
https://bugzilla.redhat.com/show_bug.cgi?id=2328846 |
|
| Applikationen: |
Red Hat build of Keycloak 26.0.8 |
|
Originalnachricht |
New Red Hat build of Keycloak 26.0.8 packages are available from the Customer Portal
Red Hat build of Keycloak 26.0.8 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.
Security fixes: * Denial of Service in Keycloak Server via Security Headers (CVE-2024-11734) * Unrestricted admin use of system and environment variables (CVE-2024-11736)
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
CVE-2024-11734: Protection Mechanism Failure (CWE-693) CVE-2024-11736: Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526)
|
|
|
|