Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_openshift_container_platform_3.11:jenkins jenkins as a component of Red Hat OpenShift Container Platform 3.11 | affected | no version stated vendor label: jenkins | no fix planned fix in another branch | csaf_redhat | |
| red_hat_openshift_container_platform_3.11:jenkins.src jenkins.src as a component of Red Hat OpenShift Container Platform 3.11 | affected | no version stated vendor label: jenkins.src | no fix planned fix in another branch | csaf_redhat | |
| 8Base-OCP-Tools-4.12:jenkins-0:2.426.3.1706515686-3.el8.noarch jenkins-0:2.426.3.1706515686-3.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.12 | fixed | jenkins-0:2.426.3.1706515686-3.el8.noarch | vendor fix → jenkins-0:2.426.3.1706515686-3.el8.noarch (RHSA-2024:0778) | csaf_redhat | |
| 8Base-OCP-Tools-4.12:jenkins-0:2.426.3.1706515686-3.el8.src jenkins-0:2.426.3.1706515686-3.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.12 | fixed | jenkins-0:2.426.3.1706515686-3.el8.src | vendor fix → jenkins-0:2.426.3.1706515686-3.el8.src (RHSA-2024:0778) | csaf_redhat | |
| 8Base-OCP-Tools-4.13:jenkins-0:2.426.3.1706516254-3.el8.noarch jenkins-0:2.426.3.1706516254-3.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.13 | fixed | jenkins-0:2.426.3.1706516254-3.el8.noarch | vendor fix → jenkins-0:2.426.3.1706516254-3.el8.noarch (RHSA-2024:0776) | csaf_redhat | |
| 8Base-OCP-Tools-4.13:jenkins-0:2.426.3.1706516254-3.el8.src jenkins-0:2.426.3.1706516254-3.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.13 | fixed | jenkins-0:2.426.3.1706516254-3.el8.src | vendor fix → jenkins-0:2.426.3.1706516254-3.el8.src (RHSA-2024:0776) | csaf_redhat | |
| 8Base-OCP-Tools-4.11:jenkins-0:2.426.3.1706516929-3.el8.noarch jenkins-0:2.426.3.1706516929-3.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8 | fixed | jenkins-0:2.426.3.1706516929-3.el8.noarch | vendor fix → jenkins-0:2.426.3.1706516929-3.el8.noarch (RHSA-2024:0775) | csaf_redhat | |
| 8Base-OCP-Tools-4.11:jenkins-0:2.426.3.1706516929-3.el8.src jenkins-0:2.426.3.1706516929-3.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8 | fixed | jenkins-0:2.426.3.1706516929-3.el8.src | vendor fix → jenkins-0:2.426.3.1706516929-3.el8.src (RHSA-2024:0775) | csaf_redhat | |
| 8Base-OCP-Tools-4.11:jenkins-2-plugins-0:4.11.1706516946-1.el8.noarch jenkins-2-plugins-0:4.11.1706516946-1.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8 | not affected vulnerable code not present | jenkins-2-plugins-0:4.11.1706516946-1.el8.noarch | not applicable | csaf_redhat | |
| 8Base-OCP-Tools-4.11:jenkins-2-plugins-0:4.11.1706516946-1.el8.src jenkins-2-plugins-0:4.11.1706516946-1.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8 | not affected vulnerable code not present | jenkins-2-plugins-0:4.11.1706516946-1.el8.src | not applicable | csaf_redhat | |
| 8Base-OCP-Tools-4.12:jenkins-2-plugins-0:4.12.1706515741-1.el8.noarch jenkins-2-plugins-0:4.12.1706515741-1.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.12 | not affected vulnerable code not present | jenkins-2-plugins-0:4.12.1706515741-1.el8.noarch | not applicable | csaf_redhat | |
| 8Base-OCP-Tools-4.12:jenkins-2-plugins-0:4.12.1706515741-1.el8.src jenkins-2-plugins-0:4.12.1706515741-1.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.12 | not affected vulnerable code not present | jenkins-2-plugins-0:4.12.1706515741-1.el8.src | not applicable | csaf_redhat | |
| 8Base-OCP-Tools-4.13:jenkins-2-plugins-0:4.13.1706516346-1.el8.noarch jenkins-2-plugins-0:4.13.1706516346-1.el8.noarch as a component of OpenShift Developer Tools and Services for OCP 4.13 | not affected vulnerable code not present | jenkins-2-plugins-0:4.13.1706516346-1.el8.noarch | not applicable | csaf_redhat | |
| 8Base-OCP-Tools-4.13:jenkins-2-plugins-0:4.13.1706516346-1.el8.src jenkins-2-plugins-0:4.13.1706516346-1.el8.src as a component of OpenShift Developer Tools and Services for OCP 4.13 | not affected vulnerable code not present | jenkins-2-plugins-0:4.13.1706516346-1.el8.src | not applicable | csaf_redhat | |
| https://github.com/jenkinsci/jenkins | affected | >= 3d8a846a753478d75141de0edd3283d7567dbf50, <= 3b0de10df3bedba515e13032104d4d84f83045be | none available | osv | |
| https://github.com/jenkinsci/jenkins | affected | >= d66bd8595e531749e842274a806eabab5cc16a32, <= 3eb70099423f93c9de29fca3c6b5b6efd2847ad0 | none available | osv | |
| jenkins | affected | >= 2.217.0, < 2.452.1 | vendor fix → 2.452.1 | osv BIT-jenkins-2024-23898 | |
| org.jenkins-ci.main:jenkins-core | affected | >= 2.217, < 2.426.3 | vendor fix → 2.426.3 | osv GHSA-53ph-2r2x-vqw8 | |
| org.jenkins-ci.main:jenkins-core | affected | >= 2.427, < 2.442 | vendor fix → 2.442 | osv GHSA-53ph-2r2x-vqw8 | |
| org.jenkins-ci.main:jenkins-core | affected | 2.441 | none available | osv GHSA-53ph-2r2x-vqw8 | |
| jenkins | fixed | 2.452.1 | vendor fix → 2.452.1 | osv BIT-jenkins-2024-23898 | |
| org.jenkins-ci.main:jenkins-core | fixed | 2.426.3 | vendor fix → 2.426.3 | osv GHSA-53ph-2r2x-vqw8 | |
| org.jenkins-ci.main:jenkins-core | fixed | 2.442 | vendor fix → 2.442 | osv GHSA-53ph-2r2x-vqw8 | |
| Jenkins Project/Jenkins Jenkins Project · Jenkins | not affected | < 2.217 | not applicable | cve_cna | |
| Jenkins Project/Jenkins Jenkins Project · Jenkins | not affected | 2.442 | not applicable | cve_cna | |
| Jenkins Project/Jenkins Jenkins Project · Jenkins | not affected | 2.426.3 | not applicable | cve_cna | |
| Jenkins Project/Jenkins Jenkins Project · Jenkins | not affected | 2.440.1 | not applicable | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.