-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Single Sign-On 7.4.10 security update Advisory ID: RHSA-2022:0446-01 Product: Red Hat Single Sign-On Advisory URL: https://access.redhat.com/errata/RHSA-2022:0446 Issue date: 2022-02-07 CVE Names: CVE-2021-4104 CVE-2022-23302 CVE-2022-23305 CVE-2022-23307 ===================================================================== 1. Summary: A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Single Sign-On 7.4 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. This release of Red Hat Single Sign-On 7.4.10 serves as a replacement for Red Hat Single Sign-On 7.4.9, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender (CVE-2022-23305) * log4j: Unsafe deserialization flaw in Chainsaw log viewer (CVE-2022-23307) * log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender (CVE-2021-4104) * log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink (CVE-2022-23302) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed (https://bugzilla.redhat.com/): 2031667 - CVE-2021-4104 log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender 2041949 - CVE-2022-23302 log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink 2041959 - CVE-2022-23305 log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender 2041967 - CVE-2022-23307 log4j: Unsafe deserialization flaw in Chainsaw log viewer 5. JIRA issues fixed (https://issues.jboss.org/): CIAM-2064 - [log4j 1.x] One-off patch for RH-SSO 7.4.10 ZIP distribution 6. References: https://access.redhat.com/security/cve/CVE-2021-4104 https://access.redhat.com/security/cve/CVE-2022-23302 https://access.redhat.com/security/cve/CVE-2022-23305 https://access.redhat.com/security/cve/CVE-2022-23307 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=core.service.rhsso&downloadType=securityPatches&version=7.4 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYgIBmdzjgjWX9erEAQghog/9H6zYaV84wXl+Hgy8OcFSGBW0O3Ch/cgg NtPDMhx7aios6HIhfF6VzsBFgG5l4gTcfQ7xy6W4Cw1nl6xWkcyx3mLJ8nvp+7qE KDqHQImTiYR4Fm3+Mnewe9bfMxzQOhFeDmhxfZwPArid2maXBKY9P/NqE5F2gbPV F3tP/LMKawYY86eDxRIRggyWVg5UmRFOZu2MCSgs0UBYU4U7HyVeuJAXHFAeCyI3 itUexd4XbuHZYDQwiUXJvGR77LHncWH0Dkg+F8ApznZXmaDoUiDfuLlZ1ZaKtcAz Nl6rQeteobLnakyKniY2PP6cLRakKA8Qy6YJFq+ieAs3t7tGzD3e0/WMQqFF5CsJ fL5yVzcNSIH6t4GWosSHwFW+tjzRmowUR+RNQKqvqRe7sdQ8wh71o2uQtDHJW/yF ROFbWMGmqX3jSxd71gCPIVUESaw4FAQkcY3GhZxs6XdGggU9YkEM1viCYdmFbYm2 idWRuScJh0vVEGXvUIFFU73C0ZSHT/+4q+b9YfYalpuw8opjH7ZQROmCkdtrOhHP UVjXwWMu2wwSHi8mX9GIpe1cKCYBg6v6EoRy+Zj9fr6MifKUrRl06/Dgty/zRmL5 BKCAUmcrctvwqK9QcSr0/K5Ts2JyV93LOC4uI6JL6/zsFBGbP2DHIDZAtbural/B fsN6uPcauEg= =UM11 -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce