Red Hat Security Advisory: Red Hat Product OCP Tools 4.12 Openshift Jenkins security update
🔗 CVE IDs covered (10)
📋 Description
CVE-2020-7692 — google-oauth-client: missing PKCE support in accordance with the RFC for OAuth 2.0 for Native Apps can lead to improper authorization CVE-2022-25857 — snakeyaml: Denial of Service due to missing nested depth limitation for collections CVE-2022-29599 — maven-shared-utils: Command injection via Commandline class CVE-2022-42889 — apache-commons-text: variable interpolation RCE CVE-2023-24422 — jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin CVE-2023-25761 — jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin CVE-2023-25762 — jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step Plugin CVE-2023-27903 — Jenkins: Temporary file parameter created with insecure permissions CVE-2023-27904 — Jenkins: Information disclosure through error stack traces related to agents CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2023:6172
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136374
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136388
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2145194
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6172.json