RHSA-2020:4223HighCVSS 7.7

Red Hat Security Advisory: OpenShift Container Platform 3.11.306 jenkins security update

Published
October 22, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2019-17638 — jetty: double release of resource can lead to information disclosure CVE-2020-2229 — jenkins: user-specified tooltip values leads to stored cross-site scripting CVE-2020-2230 — jenkins: stored XSS vulnerability in project naming strategy CVE-2020-2231 — jenkins: stored XSS vulnerability in 'trigger builds remotely'

🎯 Affected products3

  • Red Hat OpenShift Container Platform 3.11
  • jenkins-0:2.235.5.1600415953-1.el7.noarch as a component of Red Hat OpenShift Container Platform 3.11
  • jenkins-0:2.235.5.1600415953-1.el7.src as a component of Red Hat OpenShift Container Platform 3.11

✅ Remediation

See the following documentation, which will be updated shortly for release 3.11.306, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258.

🔗 References (7)