CVE-2020-2121
Published Feb 12, 2020Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution…
Vendor/product archive
2 CVEs tagged to jenkins / google_kubernetes_engine — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution…
A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/Read permission to obtain limited information about the scop…