CVEs Blog | G5 Cyber Security

CVE-2020-2158 – Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parse

Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2158

Reference (s):

Exit mobile version