RHSA-2024:8884: Important: Red Hat Product OCP Tools 4.15 Openshift Jenkins security update
Important: Red Hat Product OCP Tools 4.15 Openshift Jenkins security update
Other sources
Jenkins is a continuous integration server that monitors executions of repeated<br>jobs, such as building a software project or jobs run by cron.<br>Security Fixes:<br><li> jenkins: Item creation restriction bypass vulnerability (CVE-2024-47804)</li> <li> jenkins: Exposure of multi-line secrets through error messages (CVE-2024-47803)</li> <li> jenkins: Enabling Secure Server Identity Checks for Safer SMTPS Communication (CVE-2021-44549)</li> <li> jenkins: Denial of service when processing a specially crafted Spring Expression Language expression (CVE-2024-38808)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments,<br>and other related information, refer to the CVE page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:8884?
The severity of RHSA-2024:8884 is classified as important.
How do I fix RHSA-2024:8884?
To fix RHSA-2024:8884, update the jenkins packages to the specified versions in the advisory.
Which products are affected by RHSA-2024:8884?
RHSA-2024:8884 affects the Red Hat OpenShift Developer Tools and Services as well as specific jenkins package versions.
What security issues are addressed in RHSA-2024:8884?
RHSA-2024:8884 addresses security issues related to item creation restrictions in jenkins.
Is there a specific version of jenkins I need to upgrade to for RHSA-2024:8884?
Yes, you need to upgrade to jenkins versions 2-plugins-4.15.1729838165-1.el8 or 2.462.3.1729837947-3.el8.