Red Hat Security Advisory: OpenShift Container Platform 4.10.51 security update
🔗 CVE IDs covered (23)
📋 Description
CVE-2020-7692 — google-oauth-client: missing PKCE support in accordance with the RFC for OAuth 2.0 for Native Apps can lead to improper authorization CVE-2022-25857 — snakeyaml: Denial of Service due to missing nested depth limitation for collections CVE-2022-30946 — plugin: CSRF vulnerability in Script Security Plugin CVE-2022-30952 — plugin: User-scoped credentials exposed to other users by Pipeline SCM API for Blue Ocean Plugin CVE-2022-30953 — plugin: CSRF vulnerability in Blue Ocean Plugin CVE-2022-30954 — plugin: missing permission checks in Blue Ocean Plugin CVE-2022-36882 — jenkins-plugin: Cross-site Request Forgery (CSRF) in org.jenkins-ci.plugins:git CVE-2022-36883 — plugin: Lack of authentication mechanism in Git Plugin webhook CVE-2022-36884 — plugin: Lack of authentication mechanism in Git Plugin webhook CVE-2022-36885 — plugin: Non-constant time webhook signature comparison in GitHub Plugin CVE-2022-43401 — jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin CVE-2022-43402 — jenkins-plugin/workflow-cps: Sandbox bypass vulnerabilities in Pipeline: Groovy Plugin CVE-2022-43403 — jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin CVE-2022-43404 — jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin CVE-2022-43405 — jenkins-plugin/pipeline-groovy-lib: Sandbox bypass vulnerability in Pipeline: Groovy Libraries Plugin CVE-2022-43406 — jenkins-plugin/workflow-cps-global-lib: Sandbox bypass vulnerability in Pipeline: Deprecated Groovy Libraries Plugin CVE-2022-43407 — jenkins-plugin/pipeline-input-step: CSRF protection for any URL can be bypassed in Pipeline: Input Step Plugin CVE-2022-43408 — jenkins-plugin/pipeline-stage-view: CSRF protection for any URL can be bypassed in Pipeline: Stage View Plugin CVE-2022-43409 — jenkins-plugin/workflow-support: Stored XSS vulnerability in Pipeline: Supporting APIs Plugin CVE-2022-45047 — mina-sshd: Java unsafe deserialization vulnerability CVE-2022-45379 — jenkins-plugin/script-security: Whole-script approval in Script Security Plugin vulnerable to SHA-1 collisions CVE-2022-45380 — jenkins-plugin/JUnit: Stored XSS vulnerability in JUnit Plugin CVE-2022-45381 — jenkins-plugin/pipeline-utility-steps: Arbitrary file read vulnerability in Pipeline Utility Steps Plugin
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2023:0560
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1856376
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2116840
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119643
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119646
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119647
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119656
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119657
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119658
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2126789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136370
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136374
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136379
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136381
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136382
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136388
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136391
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143086
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143089
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143090
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2145194
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0560.json