Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Jenkins 2020 03 25 | — | If installed, upgrade OpenShift Pipeline Plugin to version 1.0.57 or later | Mar 27, 2020 | Mar 25, 2020 |
| Redhat Openshift | — | Upgrade jenkinsUpgrade jenkins-2-plugins | Mar 27, 2020 | Mar 25, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub