RHSA-2024:3636: Important: Red Hat Product OCP Tools 4.13 OpenShift Jenkins security update
Important: Red Hat Product OCP Tools 4.13 OpenShift Jenkins security update
Other sources
Jenkins is a continuous integration server that monitors the execution of<br>recurring jobs, such as software builds or cron jobs.<br>Security fixes:<br><li> jenkins-2-plugins: Git-server plugin has an arbitrary file read</li> vulnerability (CVE-2024-23899)<br><li> jenkins-plugin/script-security: Sandbox bypass occurs via crafted</li> constructor bodies (CVE-2024-34144)<br><li> jenkins-plugin/script-security: Sandbox bypass occurs via sandbox-defined</li> classes (CVE-2024-34145)<br><li> jenkins-2-plugins: HTML Publisher plugin has improper input sanitization</li> (CVE-2024-28149)<br><li> jetty: Stops accepting new connections from valid clients</li> (CVE-2024-22201)<br><li> SSH: Prefix truncation attack on Binary Packet Protocol (BPP)</li> (CVE-2023-48795)<br><li> golang-protobuf: Unmarshaling certain forms of invalid JSON in the</li> protojson.Unmarshal function causes an infinite loop in the<br>encoding/protojson and internal/encoding/json packages of Golang-protobuf<br>(CVE-2024-24786).<br><li> jenkins-2-plugins: Matrix-project plugin has a path traversal</li> vulnerability (CVE-2024-23900)<br>For more details about these security issues, including their impact, CVSS<br>scores, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3636?
The severity of RHSA-2024:3636 is classified as Important.
How do I fix RHSA-2024:3636?
To fix RHSA-2024:3636, update to the specified versions of jenkins-2-plugins or jenkins that are outlined in the advisory.
What products are affected by RHSA-2024:3636?
RHSA-2024:3636 affects the Red Hat OpenShift Developer Tools and Services and related Jenkins packages.
What vulnerabilities does RHSA-2024:3636 address?
RHSA-2024:3636 addresses vulnerabilities associated with the Git-server plugin in Jenkins.
Is there a mitigation available for RHSA-2024:3636?
The primary mitigation for RHSA-2024:3636 is to apply the recommended updates to affected packages.