RHSA-2023:3663: Important: jenkins and jenkins-2-plugins security update
Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron.Security Fix(es): xstream: Denial of Service by injecting recursive collections or maps based on element's hash values raising a stack overflow (CVE-2022-41966) json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) (CVE-2023-1370) springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern (CVE-2023-20860) log4j1-chainsaw, log4j1-socketappender: DoS via hashmap logging (CVE-2023-26464) Jenkins: XSS vulnerability in plugin manager (CVE-2023-27898) Jenkins: Temporary plugin file created with insecure permissions (CVE-2023-27899) jenkins-2-plugin: workflow-job: Stored XSS vulnerability in Pipeline: Job Plugin (CVE-2023-32977) http2-server: Invalid HTTP/2 requests cause DoS (CVE-2022-2048) springframework: BCrypt skips salt rounds for work factor of 31 (CVE-2022-22976) jettison: parser crash by stackoverflow (CVE-2022-40149) jackson-databind: deep wrapper array nesting wrt UNWRAPSINGLEVALUEARRAYS (CVE-2022-42003) jackson-databind: use of deeply nested arrays (CVE-2022-42004) jettison: Uncontrolled Recursion in JSONArray (CVE-2023-1436) jenkins-2-plugin: pipeline-utility-steps: Arbitrary file write vulnerability on agents in Pipeline Utility Steps Plugin (CVE-2023-32981) jettison: memory exhaustion via user-supplied XML or JSON data (CVE-2022-40150) Jenkins: Temporary file parameter created with insecure permissions (CVE-2023-27903) Jenkins: Information disclosure through error stack traces related to agents (CVE-2023-27904) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2-plugins-4.11.1686831822-1.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2.401.1.1686831596-3.el8
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3663?
The severity of RHSA-2023:3663 is classified as a Denial of Service vulnerability.
How do I fix RHSA-2023:3663?
To fix RHSA-2023:3663, you should update your Jenkins installation to the latest patched versions provided by Red Hat.
What software is affected by RHSA-2023:3663?
RHSA-2023:3663 affects Jenkins versions prior to 2-plugins-4.11.1686831822-1.el8 and 2.401.1.1686831596-3.el8.
What is the cause of RHSA-2023:3663?
RHSA-2023:3663 is caused by vulnerabilities in the XStream library that can lead to Denial of Service through malicious input.
Are there any workarounds for RHSA-2023:3663?
There are no recommended workarounds for RHSA-2023:3663; the best action is to apply the necessary updates.