Config File Provider Plugin up to and including version 3.4.1 improperly handled script names in its JavaScript-based UI, resulting in a stored cross-site scripting (XSS) vulnerability. Upstream patches: https://github.com/jenkinsci/config-file-provider-plugin/commit/64fba993c897ff52a9c6c38c6c41806f2e8cc73f
External References: https://jenkins.io/security/advisory/2019-01-28/#SECURITY-1253
openshift-enterprise 3.6-3.11 inclusive: affected Once openshift3/jenkins-1-rhel7, openshift3/jenkins-2-rhel7, openshift3/jenkins-slave-base-rhel7 container images have been released with these fixes, users of all versions of openshift-enterprise-3.2+ are encouraged to update these container images in their environment.