Fedora Account System
Red Hat Associate
Red Hat Customer
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage. References: https://www.jenkins.io/security/advisory/2022-02-09/#SECURITY-2602 http://www.openwall.com/lists/oss-security/2022/02/09/1
per AppSRE, Jenkins not in use in OSD
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-0538