CVE-2020-2121

Severity
8.8HIGH
EPSS
1.6%
top 18.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 24

Description

Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

3
GHSA
RCE vulnerability in Google Kubernetes Engine Plugin2022-05-24
OSV
RCE vulnerability in Google Kubernetes Engine Plugin2022-05-24
CVEList
CVE-2020-2121: Jenkins Google Kubernetes Engine Plugin 02020-02-12

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2020-02-122020-02-12