GHSA-9r3h-wm3x-v245
Dashboard / Vulnerabilities / GHSA-9r3h-wm3x-v245
Summary: RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin
Details: ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types. This results in a remote code execution (RCE) vulnerability exploitable by users able to provide YAML input files to ElasticBox Jenkins Kubernetes CI/CD Plugin’s build step.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2211, https://github.com/jenkinsci/kubernetes-ci-plugin, https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1738, http://www.openwall.com/lists/oss-security/2020/07/02/7
Affected packages
Package
Name: com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Purl: pkg:maven/com.elasticbox.jenkins-ci.plugins/kubernetes-ci
Affected ranges
Type: ECOSYSTEM
Events:
