RHEL 7 : OpenShift Container Platform 3.11 jenkins (RHSA-2019:2503)
Medium Nessus Plugin ID 127989
SynopsisThe remote Red Hat host is missing a security update.
DescriptionAn update for jenkins is now available for Red Hat OpenShift Container Platform 3.11.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron.
Security Fix(es) :
* jenkins: CSRF protection tokens did not expire (CVE-2019-10353)
* jenkins: Arbitrary file write vulnerability using file parameter definitions (CVE-2019-10352)
* jenkins: Unauthorized view fragment access (CVE-2019-10354)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
SolutionUpdate the affected jenkins package.