Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2020.3082 OpenShift Container Platform 4.4.20 jenkins-2-plugins security update 9 September 2020 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: OpenShift Container Platform 4.4.20 jenkins-2-plugins Publisher: Red Hat Operating System: Red Hat Impact/Access: Cross-site Scripting -- Remote with User Interaction Access Confidential Data -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2020-2226 CVE-2020-2225 CVE-2020-2224 CVE-2020-2190 CVE-2020-2182 CVE-2020-2181 Reference: ESB-2020.2943 ESB-2020.2850 Original Bulletin: https://access.redhat.com/errata/RHSA-2020:3625 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: OpenShift Container Platform 4.4.20 jenkins-2-plugins security update Advisory ID: RHSA-2020:3625-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2020:3625 Issue date: 2020-09-08 CVE Names: CVE-2020-2181 CVE-2020-2182 CVE-2020-2190 CVE-2020-2224 CVE-2020-2225 CVE-2020-2226 ===================================================================== 1. Summary: An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenShift Container Platform 4.4 - noarch 3. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Security Fix(es): * jenkins-2-plugins/matrix-project: Stored XSS vulnerability in single axis builds tooltips (CVE-2020-2224) * jenkins-2-plugins/matrix-project: Stored XSS vulnerability in multiple axis builds tooltips (CVE-2020-2225) * jenkins-2-plugins/matrix-auth: Stored XSS vulnerability in Matrix Authorization Strategy Plugin (CVE-2020-2226) * jenkins-credentials-binding-plugin: Information disclosure in build log when build contains no build steps (CVE-2020-2181) * jenkins-script-security-plugin: Cross-site scripting vulnerability due to configure sandboxed scripts (CVE-2020-2190) * jenkins-credentials-binding-plugin: Improper masking of secrets (CVE-2020-2182) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For OpenShift Container Platform 4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.4/release_notes/ocp-4-4-rel ease-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.4/updating/updating-cluster - - -cli.html. 5. Bugs fixed (https://bugzilla.redhat.com/): 1847337 - CVE-2020-2190 jenkins-script-security-plugin: cross-site scripting vulnerability due to configure sandboxed scripts 1847341 - CVE-2020-2181 jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps 1847348 - CVE-2020-2182 jenkins-credentials-binding-plugin: improper masking of secrets 1857436 - CVE-2020-2224 jenkins-2-plugins/matrix-project: Stored XSS vulnerability in single axis builds tooltips 1857439 - CVE-2020-2225 jenkins-2-plugins/matrix-project: Stored XSS vulnerability in multiple axis builds tooltips 1857441 - CVE-2020-2226 jenkins-2-plugins/matrix-auth: Stored XSS vulnerability in Matrix Authorization Strategy Plugin 1861840 - CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4] 6. Package List: Red Hat OpenShift Container Platform 4.4: Source: jenkins-2-plugins-4.4.1598545590-1.el7.src.rpm noarch: jenkins-2-plugins-4.4.1598545590-1.el7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-2181 https://access.redhat.com/security/cve/CVE-2020-2182 https://access.redhat.com/security/cve/CVE-2020-2190 https://access.redhat.com/security/cve/CVE-2020-2224 https://access.redhat.com/security/cve/CVE-2020-2225 https://access.redhat.com/security/cve/CVE-2020-2226 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX1d0btzjgjWX9erEAQhboQ//TW2odd0GzagIytMWcfimc8G6STG3dXIt PJLp7qZcbQXQL3VnPHY8wsl7Ke9m63sUl9TWY1QkgsJFxwq9iV+e9sN4eJMvpsIP YyDCkk9QqqL8bnNYutVOeYBltF0v2vXzqZqyfXCn9c3Kfjvjc5fqkElaGv7FTmnR Is//UMYtZ7VP+6qeh/3tsOa90VHaMXZ2H+q2AvoL9U6DXm9qfPf27zDFH04nFPVo Vk8/6JGtzJdyGWIbEZTSXt+B4RNEW6NHFbosumCGSyPdpEZNHasMycrmBAOHpDKz Xn07GgRGC8sGp8WQz7yVfKSMkKRJkt2ShHDt6g9xYvNDnt0twkoLXUVkiYl0rI0D 1/2UOKX/8kCBo9LusTbGFKWsqp6kk88BGoN2a5O2xVFBZS5fjmR85h+qP9gjJAFZ E03JVi9bE59/osY2EVWkZElLMS9kiI8UH1wKYBErZBdeHimJy6jL7WFHmrZj/Y9V u6v+iz6VffBqJ+2R7I0EsIVu6LsftTgg+N8SMmqiRN9qwYBr4ZqfrQgMNpuetaVu 0gz0ZwjP5WLvSj8/YLH1LkfXWjNnlEDnS2iyLRFh80F4NxNBQoNs69OH/gLd2V5q TS0CYOzp37E1kUeCBVRyQZH7uLElE5fvgfWs5Nfev9r9FXMFCUy/EM4t0OP1m/OE fqjnqTc1aRg= =P4ab - -----END PGP SIGNATURE----- - -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBX1hg0uNLKJtyKPYoAQgcvA//YZDsaGNDKTyFwXdOK1UAO0uxT9z5Bx13 /Z+2RGdN3C/MZP7Hs78ozEm6N6Ski+lksuOyFcLZ0u4kLLQYJWTYe1cCRXqlIgO4 EyA7GESVZAbdfg7Ud+DbY5X39Tcxb1DvWUlL4DE+irDH8MJjk/aj2w6Jh8ZrzkAW KzqWRYwowC4uC2wsNh11a49Uzre8WKoQStgxaT0gPhsThoVkrP5bRPDXTFeSHLkI BPvMDOhezSsgNlQ7U+FiiStluQlrie8LXCjmd8qIBSVvi7Kbk+yqa5N+2VM26/vq BE7m/Hf102OAhnw6fPD2B7MIRXl9gDVRPsqVDVpp4HQLxcYfW8RLGh2Xg2GMNNBX HtUhdkaS6tZEJ6XlTsDGlJE5QT/AfCqRxsls6XxyEcbbi21JaoSOfNXwP6aFzf8f KS9pgtNboAZzaYSG43WXyiTCAxikTXk4NWnEsxw6uOPGbaFk06NMc1LLAG6okn0/ DYfOGDhA7W5M6VckBr0siPpcwhp174vRqjOrQpLMp4mYXcAwmK3WuRLWXEiRwIrD YtJHtIK479mfob6TJ5r69IfgiJvOi6a23FP9w/lbx2mePWUTJTrpB3Ni7jXwPM93 UIRL30bUic8H2aO1SbX8kOdOUOdsd11vPbi8jVNyC81vPxsmpGzFyAoKtd+kViUc c4onKobw1Nk= =XLks -----END PGP SIGNATURE-----