Input validation error in Google Kubernetes Engine - CVE-2020-2121
Published: February 13, 2020
Vulnerability identifier: #VU25292
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-2121
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Jenkins
Affected software:
Google Kubernetes Engine
Google Kubernetes Engine
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the affected software does not configure its YAML parser to prevent the instantiation of arbitrary types. A remote authenticated attacker can execute arbitrary code on the system.
How to mitigate CVE-2020-2121
Install updates from vendor's website.