RHSA-2020:3519: Important: OpenShift Container Platform 4.5.7 jenkins and openshift packages security update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron.Security Fix(es): jenkins: Stored XSS vulnerability in job build time trend (CVE-2020-2220) jenkins: Stored XSS vulnerability in upstream cause (CVE-2020-2221) jenkins: Stored XSS vulnerability in 'keep forever' badge icons (CVE-2020-2222) jenkins: Stored XSS vulnerability in console links (CVE-2020-2223) kubernetes: Node disk DOS by writing to container /etc/hosts (CVE-2020-8557) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3519?
The severity of RHSA-2020:3519 is critical, indicating it may allow an attacker to execute arbitrary code.
How do I fix RHSA-2020:3519?
To fix RHSA-2020:3519, update the affected packages to the specified remedial versions provided in the advisory.
Which software is affected by RHSA-2020:3519?
RHSA-2020:3519 affects Red Hat OpenShift and Jenkins packages in specific versions within the Red Hat ecosystem.
What vulnerabilities are associated with RHSA-2020:3519?
RHSA-2020:3519 addresses multiple vulnerabilities that could potentially allow for execution of unauthorized code.
Is there a workaround for RHSA-2020:3519?
There is no official workaround for RHSA-2020:3519; applying the update is the recommended course of action.