Red Hat Security Advisory: jenkins and jenkins-2-plugins security update
🔗 CVE IDs covered (16)
📋 Description
CVE-2020-7692 — google-oauth-client: missing PKCE support in accordance with the RFC for OAuth 2.0 for Native Apps can lead to improper authorization CVE-2021-4178 — kubernetes-client: Insecure deserialization in unmarshalYaml method CVE-2021-46877 — jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode CVE-2022-22978 — springframework: Authorization Bypass in RegexRequestMatcher CVE-2022-25647 — com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson CVE-2022-40151 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40152 — woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-42889 — apache-commons-text: variable interpolation RCE CVE-2023-24422 — jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin CVE-2023-24998 — FileUpload: FileUpload DoS with excessive parts CVE-2023-25761 — jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin CVE-2023-25762 — jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step Plugin CVE-2023-27900 — Jenkins: Denial of Service attack CVE-2023-27901 — Jenkins: Denial of Service attack CVE-2023-27902 — Jenkins: Workspace temporary directories accessible through directory browser CVE-2023-27904 — Jenkins: Information disclosure through error stack traces related to agents
🎯 Affected products5
- OpenShift Developer Tools and Services for OCP 4.13
- jenkins-0:2.387.3.1684911776-3.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.13
- jenkins-0:2.387.3.1684911776-3.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.13
- jenkins-2-plugins-0:4.13.1684911916-1.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.13
- jenkins-2-plugins-0:4.13.1684911916-1.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.13
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: This flaw may be avoided by ensuring that any external inputs used with the Commons-Text lookup methods are sanitized properly. Untrusted input should always be thoroughly sanitized before using in any potentially risky situations.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2023:3299
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1856376
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034388
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2087606
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134291
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134292
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135435
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2164278
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2172298
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177630
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177634
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177638
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177646
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2185707
- externalhttps://issues.redhat.com/browse/PITEAM-10
- externalhttps://issues.redhat.com/browse/PITEAM-9
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3299.json