GHSA-w598-25hm-jqx3
Dashboard / Vulnerabilities / GHSA-w598-25hm-jqx3
Summary: RCE vulnerability in Jenkins Pipeline: AWS Steps Plugin
Details: Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types. This results in a remote code execution (RCE) vulnerability exploitable by users able to provide YAML input files to Pipeline: AWS Steps Plugin’s build steps. Pipeline: AWS Steps Plugin 1.41 configures its YAML parser to only instantiate safe types.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2166, https://github.com/jenkinsci/pipeline-aws-plugin, https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1741, http://www.openwall.com/lists/oss-security/2020/03/25/2
Affected packages
Package
Name: de.taimos:pipeline-aws
Purl: pkg:maven/de.taimos/pipeline-aws
Affected ranges
Type: ECOSYSTEM
Events:
