Red Hat Security Advisory: jenkins and jenkins-2-plugins security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2022-42889 — apache-commons-text: variable interpolation RCE CVE-2023-24422 — jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin CVE-2023-25761 — jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin CVE-2023-25762 — jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step Plugin CVE-2023-27903 — Jenkins: Temporary file parameter created with insecure permissions CVE-2023-27904 — Jenkins: Information disclosure through error stack traces related to agents
🎯 Affected products5
- OpenShift Developer Tools and Services for OCP 4.12
- jenkins-0:2.387.1.1683009767-3.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.12
- jenkins-0:2.387.1.1683009767-3.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.12
- jenkins-2-plugins-0:4.12.1683009955-1.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.12
- jenkins-2-plugins-0:4.12.1683009955-1.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.12
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: This flaw may be avoided by ensuring that any external inputs used with the Commons-Text lookup methods are sanitized properly. Untrusted input should always be thoroughly sanitized before using in any potentially risky situations.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2023:3195
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.openshift.com/container-platform/4.12/cicd/jenkins/important-changes-to-openshift-jenkins-images.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135435
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2164278
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177632
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177634
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3195.json