Red Hat Security Advisory: jenkins and jenkins-2-plugins security update
🔗 CVE IDs covered (17)
📋 Description
CVE-2022-25857 — snakeyaml: Denial of Service due to missing nested depth limitation for collections CVE-2022-29599 — maven-shared-utils: Command injection via Commandline class CVE-2022-42889 — apache-commons-text: variable interpolation RCE CVE-2023-2976 — guava: insecure temporary directory creation CVE-2023-24422 — jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin CVE-2023-25761 — jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin CVE-2023-25762 — jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step Plugin CVE-2023-35116 — jackson-databind: denial of service via cylic dependencies CVE-2023-37946 — Jenkins: Session fixation vulnerability in OpenShift Login Plugin CVE-2023-37947 — Jenkins: Open redirect vulnerability in OpenShift Login Plugin CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-40336 — jenkins-plugins: cloudbees-folder: CSRF vulnerability in Folders Plugin may approve unsandboxed scripts CVE-2023-40337 — jenkins-plugins: cloudbees-folder: CSRF vulnerability in Folders Plugin CVE-2023-40338 — jenkins-plugins: cloudbees-folder: Information disclosure in Folders Plugin CVE-2023-40339 — jenkins-plugins: config-file-provider: Improper masking of credentials in Config File Provider Plugin CVE-2023-40341 — jenkins-plugins: blueocean: CSRF vulnerability in Blue Ocean Plugin allows capturing credentials CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
🔗 References (50)
- selfhttps://access.redhat.com/errata/RHSA-2024:0777
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066479
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2126789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135435
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2164278
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215214
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215229
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222709
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222710
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232422
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232424
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232425
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232426
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242803
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/JKNS-271
- externalhttps://issues.redhat.com/browse/JKNS-289
- externalhttps://issues.redhat.com/browse/JKNS-337
- externalhttps://issues.redhat.com/browse/JKNS-344
- externalhttps://issues.redhat.com/browse/JKNS-345
- externalhttps://issues.redhat.com/browse/OCPBUGS-11158
- externalhttps://issues.redhat.com/browse/OCPBUGS-11253
- externalhttps://issues.redhat.com/browse/OCPBUGS-11254
- externalhttps://issues.redhat.com/browse/OCPBUGS-11446
- externalhttps://issues.redhat.com/browse/OCPBUGS-1357
- externalhttps://issues.redhat.com/browse/OCPBUGS-13869
- externalhttps://issues.redhat.com/browse/OCPBUGS-14111
- externalhttps://issues.redhat.com/browse/OCPBUGS-14609
- externalhttps://issues.redhat.com/browse/OCPBUGS-15646
- externalhttps://issues.redhat.com/browse/OCPBUGS-15902
- externalhttps://issues.redhat.com/browse/OCPBUGS-1709
- externalhttps://issues.redhat.com/browse/OCPBUGS-1942
- externalhttps://issues.redhat.com/browse/OCPBUGS-2099
- externalhttps://issues.redhat.com/browse/OCPBUGS-2184
- externalhttps://issues.redhat.com/browse/OCPBUGS-2318
- externalhttps://issues.redhat.com/browse/OCPBUGS-23438
- externalhttps://issues.redhat.com/browse/OCPBUGS-27388
- externalhttps://issues.redhat.com/browse/OCPBUGS-655
- externalhttps://issues.redhat.com/browse/OCPBUGS-6579
- externalhttps://issues.redhat.com/browse/OCPBUGS-6870
- externalhttps://issues.redhat.com/browse/OCPBUGS-710
- externalhttps://issues.redhat.com/browse/OCPBUGS-8377
- externalhttps://issues.redhat.com/browse/OCPBUGS-8442
- externalhttps://issues.redhat.com/browse/OCPTOOLS-244
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0777.json