RHSA-2024:8886: Important: Red Hat Product OCP Tools 4.12 Openshift Jenkins security update
Important: Red Hat Product OCP Tools 4.12 Openshift Jenkins security update
Other sources
Jenkins is a continuous integration server that monitors executions of repeatedjobs, such as building a software project or jobs run by cron.Security Fix(es): jenkins: Exposure of multi-line secrets through error messages (CVE-2024-47803) jenkins: Item creation restriction bypass vulnerability (CVE-2024-47804) jenkins: Enabling Secure Server Identity Checks for Safer SMTPS Communication (CVE-2021-44549) jenkins: Denial of service when processing a specially crafted Spring Expression Language expression (CVE-2024-38808) jenkins-2-plugins: jenkins-plugin/script-security: sandbox bypass via crafted constructor bodies (CVE-2024-34144) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments,and other related information, refer to the CVE page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:8886?
The severity of RHSA-2024:8886 is classified as important.
How do I fix RHSA-2024:8886?
To fix RHSA-2024:8886, update the jenkins packages to the specified versions in the advisory.
Which systems are affected by RHSA-2024:8886?
RHSA-2024:8886 affects Red Hat OpenShift Developer Tools and Services and specific jenkins packages on Red Hat Enterprise Linux 8.
What vulnerabilities does RHSA-2024:8886 address?
RHSA-2024:8886 addresses the exposure of multi-line strings within Jenkins.
Is there a package recommendation to resolve RHSA-2024:8886?
Yes, upgrading to jenkins 2-plugins-4.12.1730119231-1.el8 or 2.462.3.1730119132-3.el8 is recommended.