Red Hat Security Advisory: OpenShift Container Platform 3.11.306 jenkins security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2019-17638 — jetty: double release of resource can lead to information disclosure CVE-2020-2229 — jenkins: user-specified tooltip values leads to stored cross-site scripting CVE-2020-2230 — jenkins: stored XSS vulnerability in project naming strategy CVE-2020-2231 — jenkins: stored XSS vulnerability in 'trigger builds remotely'
🎯 Affected products3
- Red Hat OpenShift Container Platform 3.11
- jenkins-0:2.235.5.1600415953-1.el7.noarch as a component of Red Hat OpenShift Container Platform 3.11
- jenkins-0:2.235.5.1600415953-1.el7.src as a component of Red Hat OpenShift Container Platform 3.11
✅ Remediation
See the following documentation, which will be updated shortly for release 3.11.306, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2020:4223
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1864680
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1874830
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1875232
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1875234
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4223.json