RHSA-2016:1773: Important: Red Hat OpenShift Enterprise 2.2.10 security, bug fix, and enhancement update
OpenShift Enterprise by Red Hat is the company's cloud computingPlatform-as-a-Service (PaaS) solution designed for on-premise orprivate cloud deployments. The Jenkins continuous integration server has been updated to upstream version 1.651.2 LTS that addresses a large number of security issues, including open redirects, a potential denial of service, unsafe handling ofuser provided environment variables and several instances of sensitive information disclosure. (CVE-2014-3577, CVE-2016-0788, CVE-2016-0789,CVE-2016-0790, CVE-2016-0791, CVE-2016-0792, CVE-2016-3721, CVE-2016-3722,CVE-2016-3723, CVE-2016-3724, CVE-2016-3725, CVE-2016-3726, CVE-2016-3727,CVE-2015-7501)Space precludes documenting all of the bug fixes and enhancements in this advisory. See the OpenShift Enterprise Technical Notes, which will be updated shortly for release 2.2.10, for details about these changes:https://access.redhat.com/documentation/en-US/OpenShiftEnterprise/2/html-single/TechnicalNotes/index.html All OpenShift Enterprise 2 users are advised to upgrade to these updated packages.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2016:1773?
The severity of RHSA-2016:1773 is rated as important.
How do I fix RHSA-2016:1773?
To fix RHSA-2016:1773, update the affected Red Hat packages to their recommended versions.
What packages are affected by RHSA-2016:1773?
RHSA-2016:1773 affects various packages including jenkins, activemq, and openshift-origin components.
Is RHSA-2016:1773 related to security vulnerabilities?
Yes, RHSA-2016:1773 addresses security vulnerabilities in the Jenkins continuous integration server.
What is the update version for jenkins in RHSA-2016:1773?
The update version for jenkins in RHSA-2016:1773 is 1.651.2-1.el6.