RHSA-2024:4597HighCVSS 8.8

Red Hat Security Advisory: Red Hat Product OCP Tools 4.15 OpenShift Jenkins security update

Published
July 17, 2024
Last Modified
May 26, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-21626 — runc: file descriptor leak CVE-2024-22201 — jetty: stop accepting new connections from valid clients CVE-2024-23899 — jenkins-2-plugins: git-server plugin arbitrary file read vulnerability CVE-2024-23900 — jenkins-2-plugins: matrix-project plugin path traversal vulnerability CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28149 — jenkins-2-plugins: Improper input sanitization in HTML Publisher Plugin CVE-2024-34144 — jenkins-plugin/script-security: sandbox bypass via crafted constructor bodies CVE-2024-34145 — jenkins-plugin/script-security: sandbox bypass via sandbox-defined classes

🔗 References (12)