cbcvebase.
CVE-2020-2166
published 2020-03-25

CVE-2020-2166: Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

Affected

13 ranges
VendorProductVersion rangeFixed in
jenkinsartifactory_plugin
jenkinsaws_steps_plugin
jenkinsazure_container_service_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinsopenshift_pipeline_plugin
jenkinspipeline<= 1.40
jenkinsqueue_cleanup_plugin
jenkinsrapiddeploy_plugin
jenkinsyaml_input_files_to_azure_container_service_plugin
jenkinsyaml_input_files_to_openshift_pipeline_plugin
jenkins_projectjenkins_pipeline_aws_steps_pluginunspecified – 1.40