RHSA-2020:4220: Important: OpenShift Container Platform 4.4.27 openshift-jenkins-2-container security update
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>Security Fix(es):<br><li> jetty: Double release of resource can lead to information disclosure (CVE-2019-17638)</li> <li> jenkins: User-specified tooltip values leads to stored cross-site scripting (CVE-2020-2229)</li> <li> jenkins: Stored XSS vulnerability in project naming strategy (CVE-2020-2230)</li> <li> jenkins: Stored XSS vulnerability in 'trigger builds remotely' (CVE-2020-2231)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4220?
The severity of RHSA-2020:4220 is classified as important.
How do I fix RHSA-2020:4220?
To fix RHSA-2020:4220, update the affected packages to the latest version provided by Red Hat.
What vulnerabilities are addressed in RHSA-2020:4220?
RHSA-2020:4220 addresses a vulnerability in Jetty (CVE-2019-17638) that may lead to information disclosure.
Which versions of Red Hat OpenShift are affected by RHSA-2020:4220?
RHSA-2020:4220 affects certain versions of Red Hat OpenShift Container Platform, specifically those using Jetty in the specified context.
Is there a workaround for RHSA-2020:4220?
There are no specific workarounds listed for RHSA-2020:4220; updating to the patched version is recommended.