Bug 2143416 (CVE-2022-4039) - CVE-2022-4039 rhsso-container-image: unsecured management interface exposed to adjecent network
Summary: CVE-2022-4039 rhsso-container-image: unsecured management interface exposed t...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-4039
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2143042
TreeView+ depends on / blocked
 
Reported: 2022-11-16 21:33 UTC by Chess Hazlett
Modified: 2024-01-09 12:02 UTC (History)
10 users (show)

Fixed In Version: Red Hat Single Sign-On 7.6.2
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.
Clone Of:
Environment:
Last Closed: 2023-03-21 20:02:12 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:1047 0 None None None 2023-03-01 21:51:26 UTC

Description Chess Hazlett 2022-11-16 21:33:13 UTC
It was found that Keycloak instances launched by the Operator are configured with an unsecured management interface enabled. An attacker could use this interface to deploy malicious code, as well as access and modify potentially sensitive information in the app server configuration.

Comment 3 errata-xmlrpc 2023-03-01 21:51:24 UTC
This issue has been addressed in the following products:

  RHEL-8 based Middleware Containers

Via RHSA-2023:1047 https://access.redhat.com/errata/RHSA-2023:1047

Comment 4 Product Security DevOps Team 2023-03-21 20:02:10 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-4039


Note You need to log in before you can comment on or make changes to this bug.