Red Hat released RHSA-2016:1773 for OpenShift Enterprise 2.2, upgrading its bundled Jenkins service to upstream LTS version 1.651.2 and remediating 14 security vulnerabilities. The update addresses critical code-execution paths including unauthenticated Jenkins Remoting/JRMP RCE (CVE-2016-0788), XML-deserialization RCE through Jenkins APIs (CVE-2016-0792), and unsafe Java deserialization in Apache Commons Collections (CVE-2015-7501); it also fixes CVE-2014-3577 in Apache HttpComponents/CXF.
Additional Jenkins fixes cover HTTP response splitting, timing weaknesses affecting API tokens and CSRF crumbs, attacker-controlled build environment variables, authentication and update-metadata denial of service, plugin and configuration disclosure, encrypted-secret exposure (CVE-2016-3724), and open redirects. The release also corrects OpenShift operational defects that prevented quota-exhausted gears from being stopped, started, or moved and left stale load-balancer routes after HA gear migrations. Organizations operating OpenShift Enterprise 2.2 should apply the advisory packages after required prior errata.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-impact advisory RHSA-2016:1773 for OpenShift Enterprise 2.2, updating it to release 2.2.10 and Jenkins to 1.651.2 LTS. The update remediated Jenkins CVEs including remote code execution, response splitting, timing, denial-of-service, disclosure, environment-variable, and redirect flaws, as well as CVE-2014-3577 and CVE-2015-7501; it also delivered related OpenShift bug fixes.
QA validated the OpenShift 2.2/2016-08-08.1 build for the regression that prevented quota-exhausted gears from being unidled, upgraded, or moved. A test application at full disk quota was successfully stopped, started, and moved after temporary quota-buffer handling was added.
Red Hat released RHSA-2016:1206, a Moderate-impact update for OpenShift Enterprise 3.2 that upgraded Jenkins to 1.651.2 LTS and fixed CVE-2016-3721 through CVE-2016-3727. The update included the openshift3/jenkins-1-rhel7:1.651.2-4 container image.
Fedora released jenkins-1.625.3-4.fc23 for Fedora 23 and jenkins-1.609.3-7.fc22 for Fedora 22, delivering fixes for the affected Jenkins issues.
Fedora published jenkins-1.651.2-1.fc24 to the Fedora 24 stable repository, incorporating fixes for the Jenkins vulnerabilities later addressed in Red Hat OpenShift advisories.
Andrej Nemec reported CVE-2016-3722 through CVE-2016-3727, covering login denial of service, plugin and configuration disclosure, encrypted-secret exposure, metadata-refresh authorization, and open redirects.
The CVE record for CVE-2016-3725 was published, documenting that authenticated Jenkins users could trigger update-site metadata refreshes without a required permission check. The capability could be combined with DNS cache poisoning to disrupt service.
Jenkins published Security Advisory 2016-02-24 covering CVE-2016-0788 through CVE-2016-0792, including remoting and remote-API code execution, HTTP response splitting, and timing weaknesses in API-token and CSRF-crumb validation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
34 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcewiki.jenkins-ci.org
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.