jenkins-2.504
Chainguard
Status
Justification
Impact
The vulnerability specifically affects Red Hat OpenShift Jenkins, which includes custom OpenShift-specific integration code not present in the upstream Jenkins project. Our jenkins-2 package is built directly from the upstream jenkinsci/jenkins source code and does not include the vulnerable OpenShift integration components. Therefore, this vulnerability is not applicable to our package despite being flagged by scanners matching on the package name.
Status