Jenkins bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. External References: https://jenkins.io/security/advisory/2017-10-11/
Created jenkins tracking bugs for this issue: Affects: openshift-1 [bug 1501968]
Created jenkins tracking bugs for this issue: Affects: fedora-all [bug 1515068]
openshift3/jenkins-2-rhel7 now uses version 2.89.2 Marking Openshift Enteprise 3 as not affected.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2017-1000394