Red Hat Security Advisory: Red Hat Product OCP Tools 4.12 Openshift Jenkins security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-22201 — jetty: stop accepting new connections from valid clients CVE-2024-23899 — jenkins-2-plugins: git-server plugin arbitrary file read vulnerability CVE-2024-23900 — jenkins-2-plugins: matrix-project plugin path traversal vulnerability CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28149 — jenkins-2-plugins: Improper input sanitization in HTML Publisher Plugin CVE-2024-34144 — jenkins-plugin/script-security: sandbox bypass via crafted constructor bodies CVE-2024-34145 — jenkins-plugin/script-security: sandbox bypass via sandbox-defined classes
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2024:3635
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2260183
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2260184
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266136
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268227
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278821
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3635.json