Skip to main content
EPSS 3.5%top 12%

Red Hat Security Advisory: Red Hat Product OCP Tools 4.19 OpenShift Jenkins security update

0
High
Published: 09/23/2025 (09/23/2025, 09:44:32 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron. Security Fix(es): * jenkins: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames (CVE-2025-5115) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.

Affected software

Affected versions
=7.13.2Red HatRed Hat Offline Knowledge PortalRed Hat Offline Knowledge Portal 1.1.2amd64registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:31830a6c2976a2336f946569f10bd7d93d5a662666014e2be846311b12d2fa78_amd64Red Hat Build of Apache CamelRed Hat build of Apache Camel 4.10.6 for Spring Boot 3.4.9OpenShift Developer Tools and ServicesOpenShift Developer Tools and Services for OCP 4.19srcjenkins-0:2.516.3.1758206866-3.el9.src

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 18:21:49 UTC

Technical Analysis

The vulnerability identified as CVE-2025-5115 affects HTTP/2 implementations in Jetty components and Netty's HTTP/2 codec. It arises from an implementation weakness where malformed client requests cause server-side stream resets without triggering abuse counters, allowing attackers to bypass throttling and resource limits. This leads to excessive CPU and memory consumption, resulting in denial of service. The issue is referred to as the "MadeYouReset" attack. Red Hat has issued a security advisory and released a patch update for the Red Hat Offline Knowledge Portal container image that mitigates this vulnerability. However, no comprehensive mitigation is currently available for all affected products. The vulnerability is rated as important/high severity due to ease of exploitation and impact on service availability.

Potential Impact

Exploitation of this vulnerability can cause denial of service by exhausting server CPU and memory resources through repeated server-side stream resets triggered by malformed HTTP/2 requests. This can degrade or disrupt service availability for legitimate users. The vulnerability requires no authentication and can be exploited remotely over the network. No confidentiality or integrity impacts are reported. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released an updated container image for the Red Hat Offline Knowledge Portal that includes mitigations for CVE-2025-5115. Users should update to this version by pulling the updated container image from the Red Hat container registry using a valid subscription. Currently, no other mitigation meets Red Hat's standards for usability and stability. Users should monitor Red Hat advisories for future updates and consider applying the available update to affected products where applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:14911
Cve Count
2
Additional Cves
["CVE-2025-55163"]

Threat ID: 6a294d7f8dd33fbd853ac8a4

Added to database: 06/10/2026, 11:41:51 UTC

Last enriched: 08/16/2026, 18:21:49 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 119

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses