First published: Thu Jan 12 2023(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.8.56. See the following advisory for the container images for this release:<br><a href="https://access.redhat.com/errata/RHBA-2023:0018" target="_blank">https://access.redhat.com/errata/RHBA-2023:0018</a> Security Fix(es):<br><li> Pipeline Shared Groovy Libraries: Untrusted users can modify some</li> Pipeline libraries in Pipeline Shared Groovy Libraries Plugin<br>(CVE-2022-29047)<br><li> Jenkins plugin: Sandbox bypass vulnerability through implicitly</li> allowlisted platform Groovy files in Pipeline: Groovy Plugin<br>(CVE-2022-30945)<br><li> Jenkins plugin: Mercurial SCM plugin can check out from the controller</li> file system (CVE-2022-30948)<br><li> jenkins-plugin: Arbitrary file write vulnerability in Pipeline Input Step</li> Plugin (CVE-2022-34177)<br><li> jenkins-plugin: Man-in-the-Middle (MitM) in</li> org.jenkins-ci.plugins:git-client (CVE-2022-36881)<br><li> http2-server: Invalid HTTP/2 requests cause DoS (CVE-2022-2048)</li> <li> Jenkins plugin: CSRF vulnerability in Script Security Plugin</li> (CVE-2022-30946)<br><li> Jenkins plugin: User-scoped credentials exposed to other users by</li> Pipeline SCM API for Blue Ocean Plugin (CVE-2022-30952)<br><li> Jenkins plugin: CSRF vulnerability in Blue Ocean Plugin (CVE-2022-30953)</li> <li> Jenkins plugin: missing permission checks in Blue Ocean Plugin</li> (CVE-2022-30954)<br><li> jenkins: Observable timing discrepancy allows determining username</li> validity (CVE-2022-34174)<br><li> jenkins-plugin/junit: Stored XSS vulnerability in JUnit Plugin</li> (CVE-2022-34176)<br><li> jenkins-plugin: Cross-site Request Forgery (CSRF) in</li> org.jenkins-ci.plugins:git (CVE-2022-36882)<br><li> jenkins plugin: Lack of authentication mechanism in Git Plugin webhook</li> (CVE-2022-36883)<br><li> jenkins plugin: Lack of authentication mechanism in Git Plugin webhook</li> (CVE-2022-36884)<br><li> jenkins plugin: Non-constant time webhook signature comparison in GitHub</li> Plugin (CVE-2022-36885)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s)<br>listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins | <2-plugins-4.8.1672842762-1.el8 | 2-plugins-4.8.1672842762-1.el8 |
redhat/jenkins | <2.361.1.1672840472-1.el8 | 2.361.1.1672840472-1.el8 |
redhat/jenkins | <2-plugins-4.8.1672842762-1.el8 | 2-plugins-4.8.1672842762-1.el8 |
redhat/jenkins | <2.361.1.1672840472-1.el8 | 2.361.1.1672840472-1.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.