RHSA-2024:8887: Important: Red Hat Product OCP Tools 4.13 Openshift Jenkins security update
Important: Red Hat Product OCP Tools 4.13 Openshift Jenkins security update
Other sources
Jenkins is a continuous integration server that monitors executions of repeatedjobs, such as building a software project or jobs run by cron.Security Fix(es): jenkins: Item creation restriction bypass vulnerability (CVE-2024-47804) jenkins: Exposure of multi-line secrets through error messages (CVE-2024-47803) jenkins: Enabling Secure Server Identity Checks for Safer SMTPS Communication (CVE-2021-44549) jenkins: Denial of service when processing a specially crafted Spring Expression Language expression (CVE-2024-38808) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments,and other related information, refer to the CVE page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:8887?
The severity of RHSA-2024:8887 is classified as important.
How do I fix RHSA-2024:8887?
To fix RHSA-2024:8887, update the Jenkins package to version 2-plugins-4.13.1729840148-1.el8 or 2.462.3.1729839924-3.el8.
Which software is affected by RHSA-2024:8887?
RHSA-2024:8887 affects the OpenShift Developer Tools and Services and specific versions of the Jenkins package.
What type of vulnerability is addressed in RHSA-2024:8887?
RHSA-2024:8887 addresses a security update related to item creation restrictions in Jenkins.
When was RHSA-2024:8887 released?
RHSA-2024:8887 was released in 2024.