Created attachment 1811285 [details] jenkins screenshot Description of problem: The default jenkins2 image for OCPv4.6 on the eus-4.6 channel contains at least 2 security vulnerabilities rated as HIGH by Jenkins: CVE-2021-21672 CVE-2021-21671 https://www.jenkins.io/security/advisory/2021-06-30/ Version-Release number of selected component (if applicable): v4.6.0-202107230321.p0.git.4d96f05 How reproducible: Always Steps to Reproduce: 1. Deploy jenkin on EUS OCPv4.6 Actual results: See attached screenshot. Expected results: Customers expect to launch jenkins on the eus-4.6 OCP release with no CVEs rated as Critical or Important. Additional info: Customers can not use OCPv4.8 Jenkins images on EUS OCPv4.6 clusters.
Marking this as a duplicate of 1972366 - an update to Jenkins 2.289.2 is in progress. *** This bug has been marked as a duplicate of bug 1972366 ***