RHSA-2020:3841HighCVSS 7.7

Red Hat Security Advisory: OpenShift Container Platform 4.5.13 jenkins security update

Published
September 30, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2019-17638 — jetty: double release of resource can lead to information disclosure CVE-2020-2229 — jenkins: user-specified tooltip values leads to stored cross-site scripting CVE-2020-2230 — jenkins: stored XSS vulnerability in project naming strategy CVE-2020-2231 — jenkins: stored XSS vulnerability in 'trigger builds remotely'

🎯 Affected products3

  • Red Hat OpenShift Container Platform 4.5
  • jenkins-0:2.235.5.1600414805-1.el7.noarch as a component of Red Hat OpenShift Container Platform 4.5
  • jenkins-0:2.235.5.1600414805-1.el7.src as a component of Red Hat OpenShift Container Platform 4.5

✅ Remediation

For OpenShift Container Platform 4.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.5/release_notes/ocp-4-5-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.5/updating/updating-cluster-cli.html.

🔗 References (7)