First published: Thu Feb 09 2023(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.<br>This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.9.55. See the following advisory for the container images for this release:<br><a href="https://access.redhat.com/errata/RHSA-2023:0574" target="_blank">https://access.redhat.com/errata/RHSA-2023:0574</a> Security Fix(es):<br><li> maven-shared-utils: Command injection via Commandline class</li> (CVE-2022-29599)<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>All OpenShift Container Platform 4.9 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. <br>To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at <a href="https://docs.openshift.com/container-platform/4.9/updating/updating-cluster-cli.html" target="_blank">https://docs.openshift.com/container-platform/4.9/updating/updating-cluster-cli.html</a>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins | <2-plugins-4.9.1674644684-1.el8 | 2-plugins-4.9.1674644684-1.el8 |
redhat/jenkins | <2-plugins-4.9.1674644684-1.el8 | 2-plugins-4.9.1674644684-1.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:0573 is classified as important.
To fix RHSA-2023:0573, update the jenkins package to version 2-plugins-4.9.1674644684-1.el8.
RHSA-2023:0573 affects the Jenkins package within the Red Hat OpenShift Container Platform.
Yes, a restart of the affected application may be required to apply the updates from RHSA-2023:0573.
More details about RHSA-2023:0573 can be found in the Red Hat advisories and documentation.