jenkins-2-plugins: google-oauth-client: missing PKCE support in accordance with the RFC for OAuth 2.0 for Native Apps can lead to improper authorization (CVE-2020-7692)
jenkins-2-plugins: jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin (CVE-2023-24422)
jenkins-2-plugins: jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin (CVE-2023-25761)
snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857)
maven-shared-utils: Command injection via Commandline class (CVE-2022-29599)
jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin (CVE-2023-24422)
jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin (CVE-2023-25761)
jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step Plugin (CVE-2023-25762)
RHSA-2023:6144 [alto]: Operador de escalador automático de métricas personalizado para la actualización de seguridad de Red Hat OpenShift.
HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
RHSA-2023:6161 [alto]: Actualización de seguridad y corrección de errores del kit de herramientas de migración para contenedores (MTC) 1.7.14.
HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325)
golang: net/http: insufficient sanitization of Host header (CVE-2023-29406)
golang: crypto/tls: slow verification of certificate chains containing large RSA keys (CVE-2023-29409)
golang: html/template: improper handling of special tags within script contexts (CVE-2023-39319)
golang: html/template: improper handling of HTML-like comments within script contexts (CVE-2023-39318)
golang: crypto/tls: panic when processing post-handshake message on QUIC connections (CVE-2023-39321)
golang: crypto/tls: lack of a limit on buffered post-handshake (CVE-2023-39322)
RHSA-2023:6180 [alto]: Actualización de seguridad de contenedores de seguimiento distribuido de Red Hat OpenShift 2.9.0.
browserify-sign: upper bound check issue in dsaVerify leads to a signature forgery attack (CVE-2023-46234)
RHSA-2023:6200 [alto]: Actualizaciones de seguridad y corrección de errores de Multicluster Engine para Kubernetes 2.1.9.
HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (CVE-2023-44487)
golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325)
golang: crypto/tls: panic when processing post-handshake message on QUIC connections (CVE-2023-39321)
golang: html/template: improper handling of special tags within script contexts (CVE-2023-39319)
golang: html/template: improper handling of HTML-like comments within script contexts (CVE-2023-39318)
golang: crypto/tls: lack of a limit on buffered post-handshake (CVE-2023-39322)
RHSA-2023:6190 [alto]: actualización de seguridad de Firefox.
libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488)
RHSA-2023:6193 [alto]: actualización de seguridad de Thunderbird.
libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488)
Mozilla: Queued up rendering could have allowed websites to clickjack (CVE-2023-5721)
Mozilla: Address bar spoofing via bidirectional characters (CVE-2023-5732)
Mozilla: Large WebGL draw could have led to a crash (CVE-2023-5724)
Mozilla: WebExtensions could open arbitrary URLs (CVE-2023-5725)
Mozilla: Improper object tracking during GC in the JavaScript engine could have led to a crash (CVE-2023-5728)
Mozilla: Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4 (CVE-2023-5730)
RHSA-2023:6188 [alto]: actualización de seguridad de Firefox.
Mozilla: Queued up rendering could have allowed websites to clickjack (CVE-2023-5721)
Mozilla: Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4 (CVE-2023-5730)
libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488)
Mozilla: Large WebGL draw could have led to a crash (CVE-2023-5724)
Mozilla: WebExtensions could open arbitrary URLs (CVE-2023-5725)
Mozilla: Improper object tracking during GC in the JavaScript engine could have led to a crash. (CVE-2023-5728)
Mozilla: Address bar spoofing via bidirectional characters (CVE-2023-5732)
RHSA-2023:6202 [alto]: Actualizaciones de seguridad y corrección de errores de Red Hat Advanced Cluster Management 2.6.8.
HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (CVE-2023-44487)
golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325)
golang: crypto/tls: panic when processing post-handshake message on QUIC connections (CVE-2023-39321)
golang: html/template: improper handling of special tags within script contexts (CVE-2023-39319)
golang: html/template: improper handling of HTML-like comments within script contexts (CVE-2023-39318)
golang: crypto/tls: lack of a limit on buffered post-handshake (CVE-2023-39322)
RHSA-2023:6162 [alto]: actualización de seguridad de Firefox.
Mozilla: Queued up rendering could have allowed websites to clickjack (CVE-2023-5721)
Mozilla: Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4 (CVE-2023-5730)
libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488)
Mozilla: Large WebGL draw could have led to a crash (CVE-2023-5724)
Mozilla: WebExtensions could open arbitrary URLs (CVE-2023-5725)
Mozilla: Improper object tracking during GC in the JavaScript engine could have led to a crash. (CVE-2023-5728)
Mozilla: Address bar spoofing via bidirectional characters (CVE-2023-5732)
RHSA-2023:6130 [alto]: Actualización de seguridad y corrección de errores de OpenShift Container Platform 4.13.19.
OpenShift: modification of node role labels (CVE-2023-5408)
golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325)
RHSA-2023:6199, RHSA-2023:6198, RHSA-2023:6197, RHSA-2023:6196, RHSA-2023:6195, RHSA-2023:6189, RHSA-2023:6186 y RHSA-2023:6185 [alto]: actualizaciones de seguridad de Thunderbird y Firefox.
Mozilla: Queued up rendering could have allowed websites to clickjack (CVE-2023-5721)
Mozilla: Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4 (CVE-2023-5730)
libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488)
Mozilla: Large WebGL draw could have led to a crash (CVE-2023-5724)
Mozilla: WebExtensions could open arbitrary URLs (CVE-2023-5725)
Mozilla: Improper object tracking during GC in the JavaScript engine could have led to a crash. (CVE-2023-5728)
Mozilla: Address bar spoofing via bidirectional characters (CVE-2023-5732)
Productos afectados
RHSA-2023:6171
OpenShift Developer Tools and Services 4.11 x86_64
OpenShift Developer Tools and Services 4.11 s390x
OpenShift Developer Tools and Services 4.11 ppc64le
OpenShift Developer Tools and Services 4.11 aarch64
RHSA-2023:6172
OpenShift Developer Tools and Services 4.12 x86_64
OpenShift Developer Tools and Services 4.12 s390x
OpenShift Developer Tools and Services 4.12 ppc64le
OpenShift Developer Tools and Services 4.12 aarch64
RHSA-2023:6156
Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
RHSA-2023:6165
Red Hat Service Interconnect 1 for RHEL 9 x86_64
Red Hat Service Interconnect 1 for RHEL 8 x86_64
RHSA-2023:6129
Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
Red Hat OpenShift Container Platform 4.13 for RHEL 8 x86_64
Red Hat OpenShift Container Platform for Power 4.13 for RHEL 9 ppc64le
Red Hat OpenShift Container Platform for Power 4.13 for RHEL 8 ppc64le
Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 9 s390x
Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 8 s390x
Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 9 aarch64
Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 8 aarch64
RHSA-2023:6179
OpenShift Developer Tools and Services 4.13 x86_64
OpenShift Developer Tools and Services 4.13 s390x
OpenShift Developer Tools and Services 4.13 ppc64le
OpenShift Developer Tools and Services 4.13 aarch64
RHSA-2023:6144
Custom Metric Autoscaler 2 x86_64
RHSA-2023:6161
Red Hat Migration Toolkit 1 for RHEL 8 x86_64
RHSA-2023:6180
Red Hat OpenShift distributed tracing 2 x86_64
Red Hat OpenShift distributed tracing for Power, little endian 2 ppc64le
Red Hat OpenShift distributed tracing for IBM Z and LinuxONE 2 s390x
RHSA-2023:6200
Multicluster engine for Kubernetes Text-only Advisories x86_64
RHSA-2023:6190
Red Hat Enterprise Linux Server - AUS 8.4 x86_64
Red Hat Enterprise Linux Server - TUS 8.4 x86_64
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.4 ppc64le
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.4 x86_64
RHSA-2023:6193
Red Hat Enterprise Linux Server 7 x86_64
Red Hat Enterprise Linux Workstation 7 x86_64
Red Hat Enterprise Linux Desktop 7 x86_64
Red Hat Enterprise Linux for Power, little endian 7 ppc64le
RHSA-2023:6188
Red Hat Enterprise Linux for x86_64 9 x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.2 x86_64
Red Hat Enterprise Linux Server - AUS 9.2 x86_64
Red Hat Enterprise Linux for IBM z Systems 9 s390x
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.2 s390x
Red Hat Enterprise Linux for Power, little endian 9 ppc64le
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.2 ppc64le
Red Hat Enterprise Linux for ARM 64 9 aarch64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.2 aarch64
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
Red Hat Enterprise Linux Server for ARM 64 - 4 years of updates 9.2 aarch64
Red Hat Enterprise Linux Server for IBM z Systems - 4 years of updates 9.2 s390x
RHSA-2023:6202
Red Hat Advanced Cluster Management for Kubernetes 2 for RHEL 8 x86_64
RHSA-2023:6162
Red Hat Enterprise Linux Server 7 x86_64
Red Hat Enterprise Linux Workstation 7 x86_64
Red Hat Enterprise Linux Desktop 7 x86_64
Red Hat Enterprise Linux for IBM z Systems 7 s390x
Red Hat Enterprise Linux for Power, big endian 7 ppc64
Red Hat Enterprise Linux for Power, little endian 7 ppc64le
RHSA-2023:6130
Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
Red Hat OpenShift Container Platform 4.13 for RHEL 8 x86_64
Red Hat OpenShift Container Platform for Power 4.13 for RHEL 9 ppc64le
Red Hat OpenShift Container Platform for Power 4.13 for RHEL 8 ppc64le
Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 9 s390x
Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 8 s390x
Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 9 aarch64
Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 8 aarch64
RHSA-2023:6199
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.0 x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.0 s390x
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.0 ppc64le
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.0 aarch64
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
Red Hat Enterprise Linux Server for ARM 64 - 4 years of updates 9.0 aarch64
Red Hat Enterprise Linux Server for IBM z Systems - 4 years of updates 9.0 s390x
RHSA-2023:6198
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64
RHSA-2023:6197
Red Hat Enterprise Linux Server - AUS 8.2 x86_64
Red Hat Enterprise Linux Server - TUS 8.2 x86_64
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64
RHSA-2023:6196
Red Hat Enterprise Linux Server - AUS 8.4 x86_64
Red Hat Enterprise Linux Server - TUS 8.4 x86_64
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.4 ppc64le
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.4 x86_64
RHSA-2023:6195
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.6 x86_64
Red Hat Enterprise Linux Server - AUS 8.6 x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.6 s390x
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.6 ppc64le
Red Hat Enterprise Linux Server - TUS 8.6 x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.6 aarch64
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64
RHSA-2023:6189
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64
RHSA-2023:6186
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.6 x86_64
Red Hat Enterprise Linux Server - AUS 8.6 x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.6 s390x
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.6 ppc64le
Red Hat Enterprise Linux Server - TUS 8.6 x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.6 aarch64
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64
RHSA-2023:6185
Red Hat Enterprise Linux Server - AUS 8.2 x86_64
Red Hat Enterprise Linux Server - TUS 8.2 x86_64
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64
Riesgo
Crítico
Soluciones
Para obtener detalles sobre cómo las actualizaciones necesarias, consulte:
Para más información, cualquier otra incidencia o problema de seguridad, puede ponerse en contacto a través de nuestra dirección de correo csirt@seresco.es