RHSA-2024:3634: Important: Red Hat Product OCP Tools 4.14 OpenShift Jenkins security update
Important: Red Hat Product OCP Tools 4.14 OpenShift Jenkins security update
Other sources
Jenkins is a continuous integration server that monitors the execution of<br>recurring jobs, such as software builds or cron jobs.<br>Security fixes:<br><li> jenkins-2-plugins: Git-server plugin has an arbitrary file read</li> vulnerability (CVE-2024-23899)<br><li> jenkins-plugin/script-security: Sandbox bypass occurs via crafted</li> constructor bodies (CVE-2024-34144)<br><li> jenkins-plugin/script-security: Sandbox bypass occurs via sandbox-defined</li> classes (CVE-2024-34145)<br><li> jenkins-2-plugins: HTML Publisher plugin has improper input sanitization</li> (CVE-2024-28149)<br><li> jetty: Stops accepting new connections from valid clients</li> (CVE-2024-22201)<br><li> SSH: Prefix truncation attack on Binary Packet Protocol (BPP)</li> (CVE-2023-48795)<br><li> golang-protobuf: Unmarshaling certain forms of invalid JSON in the</li> protojson.Unmarshal function causes an infinite loop in the<br>encoding/protojson and internal/encoding/json packages of Golang-protobuf<br>(CVE-2024-24786)<br><li> jenkins-2-plugins: Matrix-project plugin has a path traversal</li> vulnerability (CVE-2024-23900)<br>For more details about these security issues, including their impact, CVSS<br>scores, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3634?
The severity of RHSA-2024:3634 is classified as Important.
How do I fix RHSA-2024:3634?
To fix RHSA-2024:3634, upgrade the Jenkins packages to the recommended versions 2-plugins-4.14.1716388016-1.el8 or 2.440.3.1716387933-3.el8.
What products are affected by RHSA-2024:3634?
RHSA-2024:3634 affects Red Hat OpenShift Developer Tools and Services along with specific Jenkins packages.
What vulnerabilities does RHSA-2024:3634 address?
RHSA-2024:3634 addresses vulnerabilities within the Git-server plugin in Jenkins.
Is RHSA-2024:3634 a mandatory update?
Yes, applying the updates from RHSA-2024:3634 is recommended to ensure security and compliance.