RHSA-2025:2223HighCVSS 8.0

Red Hat Security Advisory: Red Hat Product OCP Tools 4.12 Openshift Jenkins security update

Published
March 4, 2025
Last Modified
August 9, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2024-45339 — github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glog CVE-2024-47072 — com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream CVE-2024-47855 — json-lib: Mishandling of an unbalanced comment string in json-lib CVE-2024-52549 — jenkins-plugin/script-security: Jenkins Script Security Plugin File Disclosure Vulnerability CVE-2024-52550 — jenkins-plugin/workflow-cps: Lack of Approval Check for Rebuilt Jenkins Pipelines CVE-2024-52551 — jenkins-plugin/pipeline-model-definition: Jenkins Pipeline Declarative Plugin Allows Restart of Builds with Unapproved Jenkinsfile

🎯 Affected products5

  • OpenShift Developer Tools and Services for OCP 4.12
  • jenkins-0:2.479.3.1740464431-3.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.12
  • jenkins-0:2.479.3.1740464431-3.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.12
  • jenkins-2-plugins-0:4.12.1740464689-1.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.12
  • jenkins-2-plugins-0:4.12.1740464689-1.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.12

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (8)