RHSA-2023:6172: Critical: Red Hat Product OCP Tools 4.12 Openshift Jenkins security update
Critical: Red Hat Product OCP Tools 4.12 Openshift Jenkins security update
Other sources
Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron.Security Fix(es):CVE-2023-27904 jenkins: Information disclosure through error stack traces related to agentsCVE-2023-27903 jenkins: Temporary file parameter created with insecure permissionsCVE-2023-25762 jenkins-2-plugins: jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step PluginCVE-2023-25761 jenkins-2-plugins: jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit PluginCVE-2022-25857 jenkins-2-plugins: snakeyaml: Denial of Service due to missing nested depth limitation for collections CVE-2022-42889 jenkins-2-plugins: apache-commons-text: variable interpolation RCECVE-2020-7692 jenkins-2-plugins: google-oauth-client: missing PKCE support in accordance with the RFC for OAuth 2.0 for Native Apps can lead to improper authorizationCVE-2023-24422 jenkins-2-plugins: jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security PluginCVE-2023-25761 jenkins-2-plugins: jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit PluginCVE-2023-25762 jenkins-2-plugins: jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step PluginCVE-2022-42889 jenkins-2-plugins: apache-commons-text: variable interpolation RCECVE-2022-29599 jenkins-2-plugins: maven-shared-utils: Command injection via Commandline classCVE-2023-39325 openshift-jenkins-2-container: golang: net/http, x/net/http2: rapid stream resets can cause excessive workFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:6172?
The severity of RHSA-2023:6172 is critical.
What is the affected software for RHSA-2023:6172?
The affected software for RHSA-2023:6172 is Red Hat OpenShift Developer Tools and Services.
How do I fix RHSA-2023:6172?
To fix RHSA-2023:6172, update the Jenkins package to version 2-plugins-4.12.1698294000-1.el8 or 2.414.3.1698293911-3.el8.
What are the references for RHSA-2023:6172?
The references for RHSA-2023:6172 are: [Link1](https://access.redhat.com/errata/RHSA-2023:6172), [Link2](https://bugzilla.redhat.com/show_bug.cgi?id=2136374), [Link3](https://bugzilla.redhat.com/show_bug.cgi?id=2136386).
What are the Common Weakness Enumerations (CWE) associated with RHSA-2023:6172?
The Common Weakness Enumerations (CWE) associated with RHSA-2023:6172 are CWE-79 and CWE-77.