Input validation error in OpenShift Pipeline - CVE-2020-2167
Published: March 26, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the affected software does not configure its YAML parser to prevent the instantiation of arbitrary types. A remote authenticated attacker able to provide YAML input files can execute arbitrary code on the target system.
Affected software
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
Red Hat OpenShift Container Platform
How to mitigate CVE-2020-2167
jenkins (Red Hat package) - update to 2.204.2.1585048146-1.el7
Red Hat OpenShift Container Platform - update to 3.11.188
jenkins-2-plugins (Red Hat package) - update to 3.11.1585050035-1.el7