RHSA-2025:23492MediumCVSS 5.3
Red Hat Security Advisory: Release of Red Hat OpenShift Developer Tools - Openshift Jenkins 4.18 security update.
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-4949 — org.eclipse.jgit: XXE vulnerability in Eclipse JGit CVE-2025-67635 — org.jenkins-ci.main/jenkins-core: Jenkins HTTP connection mis-handling
🎯 Affected products9
- OpenShift Developer Tools and Services 4.18
- registry.redhat.io/ocp-tools-4/jenkins-agent-base-rhel9@sha256:12c117246b5ed9075aad4a5970015d36de17812abedec9e986ede54c9f9a944e_arm64 as a component of OpenShift Developer Tools and Services 4.18
- registry.redhat.io/ocp-tools-4/jenkins-agent-base-rhel9@sha256:50021e5ceb2ff7baf42b44e3ea6cd7f39f73d45ab8accea976b59758acacf47c_ppc64le as a component of OpenShift Developer Tools and Services 4.18
- registry.redhat.io/ocp-tools-4/jenkins-agent-base-rhel9@sha256:7ea6ed80a8ce7410d3b1abb73e575e664d3c17ea7cf6eacf852d871d4858e241_s390x as a component of OpenShift Developer Tools and Services 4.18
- registry.redhat.io/ocp-tools-4/jenkins-agent-base-rhel9@sha256:9c9bc46e0370e9ae895474f85ae374d2b69a35402615fa6f6cec196a73e340a7_amd64 as a component of OpenShift Developer Tools and Services 4.18
- registry.redhat.io/ocp-tools-4/jenkins-rhel9@sha256:60063737604433397462efda8ba499016bfe5fb8400a3eb29e3daac5a098a7ed_ppc64le as a component of OpenShift Developer Tools and Services 4.18
- registry.redhat.io/ocp-tools-4/jenkins-rhel9@sha256:639855931c885c92feff9578f03cc426fb548f15721d1231227332300d90e0ad_s390x as a component of OpenShift Developer Tools and Services 4.18
- registry.redhat.io/ocp-tools-4/jenkins-rhel9@sha256:824b0151835492c9b41077491419b938c8d231ed80208cd99b3d5fa8e206c3fb_amd64 as a component of OpenShift Developer Tools and Services 4.18
- registry.redhat.io/ocp-tools-4/jenkins-rhel9@sha256:c19b9a5471b0b496011fadb920a099a20b918ec326693e0ae5b2b306d2c7a57b_arm64 as a component of OpenShift Developer Tools and Services 4.18
✅ Remediation
It is recommended that existing users of Red Hat OpenShift Developer Tools - OpenShift Jenkins 4.18 upgrade to the latest. This update includes a newer OpenShift client (oc) version bundled in the image. If your Jenkins pipelines require a specific oc version, configure it explicitly using the Jenkins pipeline tools directive. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2025:23492
- externalhttps://access.redhat.com/security/cve/CVE-2025-4949
- externalhttps://access.redhat.com/security/cve/CVE-2025-67635
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23492.json