Lucene search

K
osvGoogleOSV:GHSA-9R3H-WM3X-V245
HistoryMay 24, 2022 - 5:22 p.m.

RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin

2022-05-2417:22:19
Google
osv.dev
5

0.007 Low

EPSS

Percentile

80.3%

ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types. This results in a remote code execution (RCE) vulnerability exploitable by users able to provide YAML input files to ElasticBox Jenkins Kubernetes CI/CD Plugin’s build step.

0.007 Low

EPSS

Percentile

80.3%

Related for OSV:GHSA-9R3H-WM3X-V245