Red Hat released Important security updates for OpenShift Jenkins in Red Hat OpenShift Developer Tools and Services 4.12 and 4.15, remediating vulnerabilities in Jenkins plugins and bundled components. The updates address arbitrary file reads, path traversal, sandbox bypass, improper input sanitization, denial-of-service conditions, SSH prefix truncation, and a Go JSON unmarshaling infinite-loop flaw across x86_64, s390x, ppc64le, and aarch64 deployments.
The advisories also address CVE-2024-22201, a Jetty HTTP/2 TLS denial-of-service vulnerability that can leak file descriptors when TCP-congested connections time out, eventually preventing affected servers from accepting legitimate connections. Red Hat provided updated Jenkins 2.440.3 packages for OpenShift 4.12 and Jenkins 2.440.3.1718879390-3.el8 with updated plugin packages for 4.15; organizations should apply the applicable OpenShift Jenkins updates.

See real exploitation activity before you spend the cycle.
60 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued critical advisory RHSA-2024:5406 for OpenShift Developer Tools and Services 4.13, providing Jenkins 2.462.1 and updated plugin packages for x86_64, s390x, ppc64le, and aarch64. The update remediated CVE-2024-43044, which enables arbitrary file reads via Jenkins agent connections and may lead to remote code execution, along with Jenkins sandbox/CSRF bypasses and Apache MINA SSHD unsafe deserialization.
Red Hat issued critical advisory RHSA-2024:5411 for OpenShift Developer Tools and Services 4.14, supplying Jenkins 2.462.1 and updated plugin packages. The update remediated CVE-2024-43044, which allows arbitrary file reads through Jenkins agent connections and can lead to remote code execution, along with older Jenkins plugin and Apache MINA SSHD flaws.
Red Hat issued Important advisory RHSA-2024:4597 for OpenShift Developer Tools and Services 4.15. Updated Jenkins and plugin packages fixed nine vulnerabilities, including CVE-2024-22201, Jenkins plugin flaws, SSH prefix truncation, golang-protobuf denial of service, and the runc Leaky Vessels issue.
Red Hat issued Important advisory RHSA-2024:3635 for OpenShift Developer Tools and Services 4.12. The update remediated eight issues, including CVE-2024-22201 and Jenkins plugin flaws for arbitrary file read, path traversal, input sanitization, and sandbox bypass.
Red Hat issued Important advisory RHSA-2024:3354, releasing Red Hat Fuse 7.13.0 for x86_64 with bug fixes, enhancements, and fixes for numerous component vulnerabilities. The update remediated issues including Jetty denial of service and request handling flaws, ActiveMQ Jolokia authenticated deserialization RCE, Tomcat request smuggling, Shiro authentication bypass, and Spring Framework URL-validation flaws.
Jenkins published SECURITY-3341 for CVE-2024-34145, affecting Script Security Plugin 1335.vf07d9ce377a_e and earlier. Users able to define and run sandboxed scripts could shadow specified classes, bypass sandbox controls, and execute arbitrary code in the Jenkins controller JVM.
Rohit Keshri reported Red Hat's tracking bug for CVE-2024-22201, a Jetty denial-of-service flaw in which leaked TCP-congested HTTP/2 TLS connections can exhaust file descriptors and prevent legitimate connections.
Red Hat issued Important advisory RHSA-2024:0775 for OpenShift Developer Tools and Services for OCP 4.11, updating Jenkins and jenkins-2-plugins packages. The update remediated 11 vulnerabilities, including Jenkins CLI arbitrary file read/RCE risk CVE-2024-23897, cross-site WebSocket hijacking CVE-2024-23898, Apache Commons Text RCE, SnakeYAML deserialization RCE, Maven command injection, and Jenkins plugin flaws.
Red Hat issued RHSA-2024:0778 for OpenShift Developer Tools and Services for OCP 4.12, updating Jenkins and Jenkins-2-plugins packages. The update remediated 24 CVEs, including Jenkins CLI arbitrary file-read/RCE risk CVE-2024-23897, cross-site WebSocket hijacking CVE-2024-23898, Jenkins plugin flaws, and Apache Commons Text RCE.
Red Hat issued Important advisory RHSA-2024:0777 for OpenShift Developer Tools and Services for OCP 4.14, updating Jenkins and Jenkins 2 plugins. The update remediated 17 CVEs, including HTTP/2 Rapid Reset, Apache Commons Text RCE, Maven command injection, SnakeYAML DoS, and multiple Jenkins plugin flaws.
Jenkins published SECURITY-3319 for CVE-2024-23899, affecting Git server Plugin 99.va_0826a_b_cdfa_d and earlier. An attacker with Overall/Read permission could use @file-path argument expansion to read arbitrary files from the Jenkins controller.
Red Hat issued Critical advisory RHSA-2023:7247 for Red Hat Fuse 7.12.1, replacing Fuse 7.12 on x86_64. The update fixed 13 vulnerabilities, including HTTP/2 Rapid Reset CVE-2023-44487, ActiveMQ OpenWire deserialization RCE CVE-2023-46604, Jetty flaws, Spring Security WebFlux security bypass, and Tomcat denial-of-service, disclosure, and request-smuggling issues.
Red Hat issued Important advisory RHSA-2023:7288 for OpenShift Developer Tools and Services 4.14, updating Jenkins and Jenkins plugins. The update remediated eight vulnerabilities, including HTTP/2 Rapid Reset flaws CVE-2023-39325 and CVE-2023-44487, Apache Commons Text RCE CVE-2022-42889, Maven Shared Utils command injection CVE-2022-29599, SnakeYAML DoS CVE-2022-25857, and Jenkins plugin flaws.
Red Hat issued critical advisory RHSA-2023:6179 for OpenShift Developer Tools and Services 4.13, updating Jenkins and Jenkins plugins. The update fixed eight vulnerabilities, including HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, Apache Commons Text RCE CVE-2022-42889, Maven Shared Utils command injection CVE-2022-29599, and Jenkins plugin flaws.
Red Hat issued RHSA-2023:6172 for OpenShift Developer Tools and Services 4.12, supplying updated jenkins-2 and jenkins-2-plugins packages for supported architectures. The update addressed Jenkins and dependency flaws including sandbox and CSRF bypasses, stored XSS, insecure temporary-file permissions, information disclosure, SnakeYAML DoS, Apache Commons Text RCE, Maven command injection, and HTTP/2 Rapid Reset.
Red Hat issued Important advisory RHSA-2023:3622 for OpenShift Developer Tools and Services for OCP 4.13, updating Jenkins and Jenkins plugins. The update remediated nine vulnerabilities, including Maven Shared Utils command injection, Jettison uncontrolled recursion, json-smart resource exhaustion, Spring Framework flaws, and Jenkins/Blue Ocean CSRF, authorization, temporary-file permission, and information-disclosure issues.
Red Hat issued Important advisory RHSA-2023:3610 for OpenShift Developer Tools and Services 4.12, updating Jenkins and Jenkins 2 plugins. The update remediated 14 vulnerabilities, including Jenkins Script Security sandbox bypass CVE-2023-24422, Pipeline: Job stored XSS CVE-2023-32977, and Pipeline Utility Steps arbitrary file write CVE-2023-32981.
Red Hat issued Important advisory RHSA-2023:3195 for OpenShift Developer Tools and Services for OCP 4.12, updating Jenkins and Jenkins 2 plugins. The update remediated six vulnerabilities, including Apache Commons Text RCE CVE-2022-42889, Jenkins Script Security sandbox bypass CVE-2023-24422, stored XSS flaws, insecure temporary-file permissions, and Jenkins agent error-stack information disclosure.
Red Hat issued critical advisory RHSA-2023:3198 for OpenShift Developer Tools and Services for OCP 4.11, updating Jenkins and Jenkins 2 plugins. The update remediated vulnerabilities including Apache Commons Text RCE, Jenkins sandbox and CSRF bypasses, Maven Shared Utils command injection, SnakeYAML flaws, unsafe deserialization, stored XSS, and Jenkins information-disclosure issues.
Red Hat issued critical advisory RHSA-2023:1064 for OpenShift Developer Tools and Services 4.12, updating Jenkins and Jenkins 2 plugins. The update remediated 15 vulnerabilities, including Jenkins plugin sandbox bypasses, CSRF bypasses, stored XSS, credential exposure, unsafe deserialization, and Jackson databind denial-of-service flaws.
Red Hat issued critical advisory RHSA-2023:0777 for RHEL 8-based OpenShift Container Platform 4.9, releasing version 4.9.56 RPM packages. The update remediated 26 CVEs affecting Jenkins and plugins, SnakeYAML, Google OAuth Client, Apache MINA SSHD, and http2-server; corresponding container images were provided through RHSA-2023:0778.
Jenkins published SECURITY-3032 for CVE-2023-25761, a stored cross-site scripting flaw in JUnit Plugin 1166.va_436e268e972 and earlier. Attackers able to control test-case class names in processed JUnit resources could inject script because those names were not escaped in JavaScript expressions.
Jenkins disclosed CVE-2023-25762 (SECURITY-3019), a stored cross-site scripting flaw affecting Pipeline: Build Step Plugin 2.18 and earlier. The Pipeline Snippet Generator failed to escape attacker-controlled job names inserted into a JavaScript expression.
Red Hat issued critical advisory RHSA-2023:0560 for OpenShift Container Platform 4.10, releasing version 4.10.51 packages and images. The update remediated 23 CVEs, primarily in Jenkins plugins, including sandbox bypasses, CSRF and stored-XSS flaws, credential exposure, arbitrary file read, webhook-authentication weaknesses, plus flaws in google-oauth-client, SnakeYAML, and Apache MINA sshd.
Jenkins disclosed CVE-2023-24422 in Script Security Plugin 1228.vd93135a_2fb_25 and earlier. Groovy property assignments during map-constructor invocation bypassed sandbox allowlist interception, enabling users permitted to run sandboxed scripts or Pipelines to execute arbitrary code in the Jenkins controller JVM.
Red Hat issued Moderate advisory RHSA-2023:0189, replacing Red Hat AMQ Streams 2.2.0 with version 2.3.0. The update fixed six vulnerabilities in Jetty, HTTP/2 Server, Jackson Databind, and SnakeYAML, including CVE-2022-2048, CVE-2022-42003, and CVE-2022-42004.
Red Hat released Important-security-impact advisory RHSA-2023:0017 for OpenShift Container Platform 4.8, providing version 4.8.56 packages and images. The update remediated Jenkins and plugin flaws including sandbox bypasses, arbitrary file write, CSRF, stored XSS, credential exposure, webhook weaknesses, and the Jetty HTTP/2 denial-of-service flaw CVE-2022-2048.
Patrick Del Bello described CVE-2022-45047 in Apache MINA SSHD 2.9.1 and earlier. The SimpleGeneratorHostKeyProvider deserializes a serialized Java PrivateKey when loading an SSH server host key, creating an unsafe Java deserialization risk.
Jenkins disclosed CVE-2022-45381 (SECURITY-2949) in Pipeline Utility Steps Plugin 2.13.1 and earlier. Attackers able to configure Pipelines could abuse unrestricted Apache Commons Configuration prefix interpolators, including the default-enabled `file:` interpolator, to read arbitrary files from the Jenkins controller.
Avinash Hanwate reported CVE-2022-43408 in Jenkins Pipeline: Stage View Plugin 2.26 and earlier. Improper encoding of Pipeline input-step IDs could allow an attacker able to configure Pipelines to bypass Jenkins CSRF protection for an arbitrary target URL; version 2.27 fixed the issue.
Avinash Hanwate reported CVE-2022-43406 in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier. An attacker permitted to define untrusted Pipeline libraries and run sandboxed scripts could bypass the Jenkins sandbox and execute arbitrary code in the controller JVM; version 588.v576c103a_ff86 fixes the flaw.
Red Hat tracked CVE-2022-43404, an urgent Jenkins Script Security Plugin sandbox bypass affecting version 1183.v774b_0b_0a_a_451 and earlier. Users permitted to run sandboxed scripts could use crafted constructor bodies and synthetic constructors to escape the sandbox and execute arbitrary code in the Jenkins controller JVM; Jenkins fixed it in version 1184.v85d16b_d851b_3.
Avinash Hanwate reported CVE-2022-43401, a Jenkins Script Security Plugin sandbox bypass affecting version 1183.v774b_0b_0a_a_451 and earlier. Users permitted to define and run sandboxed scripts, including Pipelines, could exploit implicit Groovy runtime casts to bypass sandbox protections and execute arbitrary code in the Jenkins controller JVM; version 1184.v85d16b_d851b_3 fixes the flaw.
Red Hat reported CVE-2022-43403 in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier. An authorized user able to run sandboxed scripts could cast an array-like value to an array type to bypass sandbox protections and execute code in the Jenkins controller JVM; Jenkins fixed it in version 1184.v85d16b_d851b_3.
Jenkins disclosed CVE-2022-43405 in Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier. An attacker permitted to define untrusted Pipeline libraries and run sandboxed scripts could bypass sandbox protections and execute arbitrary code in the Jenkins controller JVM; versions 612.614.v48dcb_f62a_640 and 613.v9c41a_160233f fix the flaw.
Jenkins disclosed CVE-2022-43402 (SECURITY-2824), a sandbox bypass in Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier. An authorized user able to run sandboxed Pipeline scripts could abuse implicit Groovy runtime casts to bypass sandbox protections and execute arbitrary code in the Jenkins controller JVM; version 2803.v1a_f77ffcc773 fixes the flaw.
Jenkins disclosed CVE-2022-43407 in Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier. A crafted, insufficiently sanitized and URL-encoded input-step ID could let an attacker able to configure Pipelines bypass Jenkins CSRF protection for a target URL when a user interacted with the input step.
Tej Rathi reported CVE-2022-40150, a denial-of-service flaw in Jettison where crafted attacker-controlled XML or JSON input can exhaust parser memory and cause an out-of-memory crash. Jettison 1.5.1 was referenced as addressing the issue.
Patrick Del Bello reported CVE-2022-2048 to Red Hat as Bug 2116952. Invalid HTTP/2 requests could trigger Jetty error handling that left connections and resources active, allowing resource exhaustion and denial of service; fixes were released in http2-server 9.4.47, 10.0.10, and 11.0.10.
Anten Skrabec reported CVE-2022-1962, in which Go Parse functions processing source code with deeply nested types or declarations can exhaust the stack and panic, causing denial of service. Red Hat tracked the issue for Fedora and EPEL and issued fixes for RHEL, Developer Tools, and multiple OpenShift- and Kubernetes-related products.
Red Hat issued Moderate-security advisory RHSA-2022:1715 for Advanced Cluster Management for Kubernetes 2.3.10, providing updated RHEL 7 and RHEL 8 x86_64 container images. The update remediated CVE-2022-0613 and other flaws in follow-redirects, node-fetch, URI.js, nconf, and Moment.js, including information exposure, protocol-validation bypass, prototype pollution, and path traversal.
Red Hat issued Moderate-severity RHSA-2022:1681 for Advanced Cluster Management for Kubernetes 2.4.4, providing updated container images for RHEL 7 and RHEL 8 x86_64 deployments. The update remediated CVE-2022-0613 and numerous other third-party flaws, including vm2 sandbox bypass, golang.org/x/crypto denial of service, data-exposure issues, nats-server privilege escalation, node-forge signature-forgery weaknesses, and URI.js validation bypasses.
Sandipan Roy reported CVE-2022-0613, an authorization-bypass vulnerability affecting URI.js (urijs) before 1.19.8 in which a user-controlled key could bypass authorization. URI.js fixed the issue upstream, and Red Hat later remediated affected Advanced Cluster Management for Kubernetes and Red Hat Fuse releases.
Red Hat issued Important advisory RHSA-2021:0429 for OpenShift Container Platform 4.5.33, supplying updated RPM packages for RHEL 7 and RHEL 8 across x86_64, ppc64le, and s390x. The update fixed 13 Jenkins and Apache Ant vulnerabilities, including the Jenkins workspace arbitrary file-read flaw CVE-2021-21602, path traversal, XSS, denial-of-service, permission-check, and insecure temporary-file flaws.
Red Hat issued Important advisory RHSA-2021:0423 for OpenShift Container Platform 4.6.17, providing updated packages for RHEL 7 and RHEL 8 on x86_64, ppc64le, and s390x. The update fixed 13 Jenkins and Apache Ant vulnerabilities, including the workspace arbitrary file-read flaw CVE-2021-21602, path traversal, cross-site scripting, deserialization, permission-check, denial-of-service, and insecure temporary-file flaws.
Red Hat published CVE-2021-21615, a Moderate Jenkins vulnerability in which a TOCTOU race in workspace and archived-artifact file browsing could allow low-privileged network attackers to read arbitrary files. Red Hat fixed affected OpenShift Container Platform 4.5 and 4.6 Jenkins components through RHSA-2021:0429 and RHSA-2021:0423; OpenShift 3.11 was designated will not fix.
Red Hat tracked CVE-2022-25857, in which SnakeYAML versions before 1.31 can be denied service through deeply nested YAML collections. Red Hat remediated affected RHEL and middleware products through multiple RHSA advisories, while acknowledging that an initially omitted prometheus-jmx-exporter-openjdk8 subpackage required corrected builds.
Red Hat addressed Jenkins Remoting arbitrary file-read vulnerability CVE-2024-43044 in OCP-Tools-4.12-RHEL-8 through RHSA-2024:5410 and OCP-Tools-4.15-RHEL-8 through RHSA-2024:5405. The flaw in ClassLoaderProxy#fetchJar allowed Jenkins agent processes to read arbitrary files from the controller and could lead to remote code execution.
Red Hat addressed CVE-2024-22201 in its build of Apache Camel 4.4.1 for Spring Boot through RHSA-2024:4884.
Red Hat addressed CVE-2024-22201 in its build of Apicurio Registry 2.6.1 GA through RHSA-2024:4873.
Red Hat addressed the Jetty CVE-2024-22201 denial-of-service vulnerability for OCP-Tools-4.14-RHEL-8 through RHSA-2024:3634.
Red Hat addressed the Jetty CVE-2024-22201 denial-of-service vulnerability for OCP-Tools-4.13-RHEL-8 through RHSA-2024:3636.
Red Hat addressed Jenkins CLI arbitrary file-read vulnerability CVE-2024-23897 in OpenShift Developer Tools and Services for OCP 4.13 through RHSA-2024:0776. The flaw allowed unauthenticated attackers to use Jenkins CLI @-file argument expansion to read files accessible to the Jenkins controller.
Red Hat tracked CVE-2023-36478, an integer-overflow flaw in Jetty HTTP/2 HPACK header-size validation that can let crafted Huffman-encoded headers trigger excessive buffer allocation and denial of service. Eclipse fixed the issue in Jetty 9.4.53, 10.0.16, and 11.0.16; Red Hat remediated affected Fuse 7.12.1 and 7.13.0 releases through security advisories.
Red Hat closed its tracking bug for CVE-2022-42004, a jackson-databind resource-exhaustion flaw caused by missing depth validation in BeanDeserializer._deserializeFromArray when processing deeply nested arrays. Red Hat issued product advisories for affected offerings including OpenShift Logging, JBoss AMQ, Quarkus, Vert.x, AMQ Streams, JBoss EAP, Data Grid, Single Sign-On, Satellite, and Process Automation.
Red Hat tracked CVE-2022-42889, affecting Apache Commons Text 1.5 through 1.9, where default script, DNS, and URL interpolation lookups can execute scripts or make unintended outbound requests when applications interpolate untrusted values. Apache Commons Text 1.10.0 disables the dangerous lookups by default.
Red Hat's Product Security DevOps Team closed its tracking bug for CVE-2022-42003, a jackson-databind resource-exhaustion flaw caused by missing nesting-depth validation when UNWRAP_SINGLE_VALUE_ARRAYS is enabled. The flaw was fixed upstream in jackson-databind 2.13.4.1, 2.12.17.1, and 2.14.0-rc1, with Red Hat advisories issued for affected products.
Red Hat closed its tracking bug for CVE-2022-40149, a Jettison XML/JSON parser denial-of-service flaw where crafted untrusted input can cause a stack overflow and crash the parser. Jettison 1.5.1 addresses the issue, with Red Hat remediation later issued across multiple products.
Red Hat tracked CVE-2022-29599, a command-injection flaw in Apache Maven Shared Utils where Commandline could emit inadequately escaped double-quoted strings. Apache's upstream MSHARED-297 remediation changed BourneShell quoting to consistently single-quote emitted strings and safely encode embedded single quotes.
Red Hat tracked CVE-2021-21602, a path-traversal vulnerability in Jenkins 2.274 and earlier and LTS 2.263.1 and earlier. Attackers could follow symbolic links through workspace and archived-artifact file browsers to read arbitrary files; Red Hat remediated affected OpenShift Container Platform 4.5 and 4.6 releases through RHSA-2021:0429 and RHSA-2021:0423.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.