Observable discrepancy in Jenkins and Jenkins LTS - CVE-2022-34174

 

Observable discrepancy in Jenkins and Jenkins LTS - CVE-2022-34174

Published: June 23, 2022


Vulnerability identifier: #VU64604
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-34174
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to observable discrepancy issue in the login form. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

Jenkins
Jenkins LTS
Red Hat OpenShift GitOps
Red Hat OpenShift Container Platform
jenkins (Red Hat package)
python-sushy (Red Hat package)
jenkins-2-plugins (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
openshift-kuryr (Red Hat package)
openshift-clients (Red Hat package)

How to mitigate CVE-2022-34174

Install updates from vendor's website.

Jenkins - update to 2.356
Jenkins LTS - update to 2.332.4
Red Hat OpenShift Container Platform - addressed in versions 4.8.56, 4.9.56, 4.10.52
jenkins (Red Hat package) - addressed in versions 2.361.1.1672840472-1.el8, 2.361.1.1675406172-1.el8, 2.361.1.1675668150-1.el8
python-sushy (Red Hat package) - update to 4.1.5-0.20221125154417.ff95176.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675407676-1.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.10.0-202302072053.p0.ga0f9090.assembly.stream.el8
openshift (Red Hat package) - addressed in versions 4.10.0-202302072053.p0.g8a6bfe4.assembly.stream.el7, 4.10.0-202302072053.p0.g8a6bfe4.assembly.stream.el8
openshift-ansible (Red Hat package) - addressed in versions 4.10.0-202302072053.p0.g72c7be6.assembly.stream.el7, 4.10.0-202302072053.p0.g72c7be6.assembly.stream.el8
openshift-kuryr (Red Hat package) - update to 4.10.0-202302072053.p0.gd4f4d9a.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.10.0-202302072053.p0.gdaed147.assembly.stream.el7, 4.10.0-202302072053.p0.gdaed147.assembly.stream.el8

External References

Related Security Bulletins