Red Hat Security Advisory: Red Hat Single Sign-On 7.6.9 security update on RHEL 8
Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. This release of Red Hat Single Sign-On 7.6.9 on RHEL 8 serves as a replacement for Red Hat Single Sign-On 7.6.8, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * exposure of sensitive information in Pushed Authorization Requests (PAR) KC_RESTART cookie (CVE-2024-4540) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
CVE-2024-4540 affects Red Hat Single Sign-On 7.6, a standalone authentication server based on Keycloak, specifically on RHEL 9. The vulnerability concerns exposure of sensitive information through Pushed Authorization Requests (PAR) involving the KC_RESTART cookie. Red Hat released version 7.6.9 as a security update to address this issue. The advisory classifies the impact as low severity and does not provide a CVSS score. The update is available as package rh-sso7-keycloak-18.0.14-1.redhat_00001.1.el9sso for RHEL 9 x86_64.
Potential Impact
The vulnerability allows exposure of sensitive information related to the KC_RESTART cookie in Pushed Authorization Requests. The impact is rated low by Red Hat, indicating limited risk or exploitability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released version 7.6.9 of Single Sign-On for RHEL 9 to address this vulnerability. Users should apply this update after ensuring all previous relevant errata are applied. Detailed update instructions are available from Red Hat's official documentation. No additional mitigation steps are indicated by the vendor.
Red Hat Security Advisory: Red Hat Single Sign-On 7.6.9 security update on RHEL 8
Description
Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. This release of Red Hat Single Sign-On 7.6.9 on RHEL 8 serves as a replacement for Red Hat Single Sign-On 7.6.8, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * exposure of sensitive information in Pushed Authorization Requests (PAR) KC_RESTART cookie (CVE-2024-4540) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-4540 affects Red Hat Single Sign-On 7.6, a standalone authentication server based on Keycloak, specifically on RHEL 9. The vulnerability concerns exposure of sensitive information through Pushed Authorization Requests (PAR) involving the KC_RESTART cookie. Red Hat released version 7.6.9 as a security update to address this issue. The advisory classifies the impact as low severity and does not provide a CVSS score. The update is available as package rh-sso7-keycloak-18.0.14-1.redhat_00001.1.el9sso for RHEL 9 x86_64.
Potential Impact
The vulnerability allows exposure of sensitive information related to the KC_RESTART cookie in Pushed Authorization Requests. The impact is rated low by Red Hat, indicating limited risk or exploitability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released version 7.6.9 of Single Sign-On for RHEL 9 to address this vulnerability. Users should apply this update after ensuring all previous relevant errata are applied. Detailed update instructions are available from Red Hat's official documentation. No additional mitigation steps are indicated by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:3568
- Cve Count
- 1
Threat ID: 6a71feeabf8831d539ff090f
Added to database: 08/04/2026, 15:02:02 UTC
Last enriched: 08/04/2026, 15:07:55 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 32
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.