RHSA-2025:16457HighCVSS 7.5

Red Hat Security Advisory: Red Hat Product OCP Tools 4.16 OpenShift Jenkins security update

Published
September 23, 2025
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-5115 — jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames

🎯 Affected products5

  • OpenShift Developer Tools and Services for OCP 4.16
  • jenkins-0:2.516.3.1758336945-3.el9.noarch as a component of OpenShift Developer Tools and Services for OCP 4.16
  • jenkins-0:2.516.3.1758336945-3.el9.src as a component of OpenShift Developer Tools and Services for OCP 4.16
  • jenkins-2-plugins-0:4.16.1758337173-1.el9.noarch as a component of OpenShift Developer Tools and Services for OCP 4.16
  • jenkins-2-plugins-0:4.16.1758337173-1.el9.src as a component of OpenShift Developer Tools and Services for OCP 4.16

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

🔗 References (4)