Red Hat Security Advisory: Red Hat Product OCP Tools 4.12 Openshift Jenkins security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2021-44549 — angus-mail: Enabling Secure Server Identity Checks for Safer SMTPS Communication CVE-2024-34144 — jenkins-plugin/script-security: sandbox bypass via crafted constructor bodies CVE-2024-38808 — spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression CVE-2024-47803 — jenkins: Exposure of multi-line secrets through error messages CVE-2024-47804 — jenkins: Item creation restriction bypass vulnerability
🎯 Affected products5
- OpenShift Developer Tools and Services for OCP 4.12
- jenkins-0:2.462.3.1730119132-3.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.12
- jenkins-0:2.462.3.1730119132-3.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.12
- jenkins-2-plugins-0:4.12.1730119231-1.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.12
- jenkins-2-plugins-0:4.12.1730119231-1.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.12
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is ei ther not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.