RHSA-2023:3663HighCVSS 8.8

Red Hat Security Advisory: jenkins and jenkins-2-plugins security update

Published
June 19, 2023
Last Modified
August 6, 2026

🔗 CVE IDs covered (17)

📋 Description

CVE-2022-2048 — http2-server: Invalid HTTP/2 requests cause DoS CVE-2022-22976 — springframework: BCrypt skips salt rounds for work factor of 31 CVE-2022-40149 — jettison: parser crash by stackoverflow CVE-2022-40150 — jettison: memory exhaustion via user-supplied XML or JSON data CVE-2022-41966 — xstream: Denial of Service by injecting recursive collections or maps based on element's hash values raising a stack overflow CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays CVE-2023-1370 — json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) CVE-2023-1436 — jettison: Uncontrolled Recursion in JSONArray CVE-2023-20860 — springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern CVE-2023-26464 — log4j1-socketappender: DoS via hashmap logging CVE-2023-27898 — Jenkins: XSS vulnerability in plugin manager CVE-2023-27899 — Jenkins: Temporary plugin file created with insecure permissions CVE-2023-27903 — Jenkins: Temporary file parameter created with insecure permissions CVE-2023-27904 — Jenkins: Information disclosure through error stack traces related to agents CVE-2023-32977 — jenkins-2-plugin: workflow-job: Stored XSS vulnerability in Pipeline: Job Plugin CVE-2023-32981 — jenkins-2-plugin: pipeline-utility-steps: Arbitrary file write vulnerability on agents in Pipeline Utility Steps Plugin

🎯 Affected products5

  • OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8
  • jenkins-0:2.401.1.1686831596-3.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8
  • jenkins-0:2.401.1.1686831596-3.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8
  • jenkins-2-plugins-0:4.11.1686831822-1.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8
  • jenkins-2-plugins-0:4.11.1686831822-1.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (20)