RHSA-2024:8885: Important: Red Hat Product OCP Tools 4.14 Openshift Jenkins security update
Important: Red Hat Product OCP Tools 4.14 Openshift Jenkins security update
Other sources
Jenkins is a continuous integration server that monitors executions of repeatedjobs, such as building a software project or jobs run by cron.Security Fixes: jenkins: Item creation restriction bypass vulnerability (CVE-2024-47804) jenkins: Exposure of multi-line secrets through error messages (CVE-2024-47803) jenkins: Enabling Secure Server Identity Checks for Safer SMTPS Communication (CVE-2021-44549) jenkins: Denial of service when processing a specially crafted Spring Expression Language expression (CVE-2024-38808) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments,and other related information, refer to the CVE page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:8885?
The severity of RHSA-2024:8885 is classified as important.
How do I fix RHSA-2024:8885?
To address RHSA-2024:8885, you should update the affected Jenkins packages to the recommended versions provided by Red Hat.
What products are affected by RHSA-2024:8885?
RHSA-2024:8885 affects Red Hat OpenShift Developer Tools and Services, specifically versions of the Jenkins package.
What kind of security vulnerabilities does RHSA-2024:8885 address?
RHSA-2024:8885 addresses security vulnerabilities related to item creation restrictions in Jenkins.
When was the RHSA-2024:8885 advisory released?
The RHSA-2024:8885 advisory was released on January 10, 2024.