Red Hat Security Advisory: Red Hat Product OCP Tools 4.13 OpenShift Jenkins security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2024-57699 — json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370) CVE-2025-1948 — jetty-http2-common: Jetty HTTP/2 Header List Size Vulnerability CVE-2025-22228 — spring-security-core: Spring Security BCryptPasswordEncoder does not enforce maximum password length CVE-2025-52999 — com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError
🎯 Affected products5
- OpenShift Developer Tools and Services for OCP 4.13
- jenkins-0:2.504.2.1750916374-3.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.13
- jenkins-0:2.504.2.1750916374-3.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.13
- jenkins-2-plugins-0:4.13.1750916671-1.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.13
- jenkins-2-plugins-0:4.13.1750916671-1.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.13
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat Product Security does not have a recommended mitigation at this time. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, the recommendation is to avoid parsing input files from untrusted sources that may have excessively deep nested data structures; anything with a depth over 1000.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:10119
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344073
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2353507
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2365137
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2374804
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_10119.json