RHSA-2024:0777: Important: jenkins and jenkins-2-plugins security update
Important: jenkins and jenkins-2-plugins security update
Other sources
Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron.Security Fix(es): golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) apache-commons-text: variable interpolation RCE (CVE-2022-42889) snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857) maven-shared-utils: Command injection via Commandline class (CVE-2022-29599) jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin (CVE-2023-24422) Jenkins: Session fixation vulnerability in OpenShift Login Plugin (CVE-2023-37946) jenkins-plugins: cloudbees-folder: CSRF vulnerability in Folders Plugin may approve unsandboxed scripts (CVE-2023-40336) guava: insecure temporary directory creation (CVE-2023-2976) jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin (CVE-2023-25761) jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step Plugin (CVE-2023-25762) jackson-databind: denial of service via cylic dependencies (CVE-2023-35116) Jenkins: Open redirect vulnerability in OpenShift Login Plugin (CVE-2023-37947) jenkins-plugins: cloudbees-folder: CSRF vulnerability in Folders Plugin (CVE-2023-40337) jenkins-plugins: cloudbees-folder: Information disclosure in Folders Plugin (CVE-2023-40338) jenkins-plugins: config-file-provider: Improper masking of credentials in Config File Provider Plugin (CVE-2023-40339) jenkins-plugins: blueocean: CSRF vulnerability in Blue Ocean Plugin allows capturing credentials (CVE-2023-40341) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0777?
RHSA-2024:0777 is categorized as an important security update.
How do I fix RHSA-2024:0777?
To remediate RHSA-2024:0777, update your Jenkins installations to the specified remedial package versions.
Which versions of Jenkins are affected by RHSA-2024:0777?
RHSA-2024:0777 affects Jenkins versions prior to 2.426.3.1706516352-3.el8 and certain plugins versions.
What types of products are impacted by RHSA-2024:0777?
RHSA-2024:0777 impacts Red Hat's OpenShift Developer Tools and Services and specific Jenkins packages.
Is there a known vulnerability described in RHSA-2024:0777?
Yes, RHSA-2024:0777 addresses security issues related to rapid stream resets in the golang net/http and x/net/http2 packages.