RHSA-2025:23486MediumCVSS 5.3
Red Hat Security Advisory: Release of Red Hat OpenShift Developer Tools - Openshift Jenkins 4.15 security update.
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-4949 — org.eclipse.jgit: XXE vulnerability in Eclipse JGit CVE-2025-67635 — org.jenkins-ci.main/jenkins-core: Jenkins HTTP connection mis-handling
🎯 Affected products9
- OpenShift Developer Tools and Services 4.15
- registry.redhat.io/ocp-tools-4/jenkins-agent-base-rhel8@sha256:2cf352e9c89a8f4bce884f49629b7c84e1352c5cd64e095ae26c2664ecc6bd89_amd64 as a component of OpenShift Developer Tools and Services 4.15
- registry.redhat.io/ocp-tools-4/jenkins-agent-base-rhel8@sha256:b0095ccfcf007894612189549ae7d931bb40fe52a923b963b678d5a6c67022e6_s390x as a component of OpenShift Developer Tools and Services 4.15
- registry.redhat.io/ocp-tools-4/jenkins-agent-base-rhel8@sha256:cc5db9e93a9e2fccd44aef2bdf018943cce058c35d11977326003481b65a866f_arm64 as a component of OpenShift Developer Tools and Services 4.15
- registry.redhat.io/ocp-tools-4/jenkins-agent-base-rhel8@sha256:e3d5be4a078ae7954f167f855d15bb0f6fc34b426928a26ff4d30b41f41549a4_ppc64le as a component of OpenShift Developer Tools and Services 4.15
- registry.redhat.io/ocp-tools-4/jenkins-rhel8@sha256:27db4f7a070211cfe9a0383cf784a664fcbe3a82605611f9f9d8c99cf93c31aa_amd64 as a component of OpenShift Developer Tools and Services 4.15
- registry.redhat.io/ocp-tools-4/jenkins-rhel8@sha256:5725ed192b1a3ca65c9087d2a56636ef31a6523549199d3a10c9a264f9137a0c_s390x as a component of OpenShift Developer Tools and Services 4.15
- registry.redhat.io/ocp-tools-4/jenkins-rhel8@sha256:f65d9a4294ddd451e0b55424085cd650591f4c72e01d931f384af4c844ec3a9b_ppc64le as a component of OpenShift Developer Tools and Services 4.15
- registry.redhat.io/ocp-tools-4/jenkins-rhel8@sha256:feffbd0107486c090d01b1b39a7b559642074d8251962cd3c0e15f6f0c3a21e5_arm64 as a component of OpenShift Developer Tools and Services 4.15
✅ Remediation
It is recommended that existing users of Red Hat OpenShift Developer Tools - OpenShift Jenkins 4.15 upgrade to the latest. This update includes a newer OpenShift client (oc) version bundled in the image. If your Jenkins pipelines require a specific oc version, configure it explicitly using the Jenkins pipeline tools directive. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2025:23486
- externalhttps://access.redhat.com/security/cve/CVE-2025-4949
- externalhttps://access.redhat.com/security/cve/CVE-2025-67635
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23486.json