Description
Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
Remediation
References
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1731
http://www.openwall.com/lists/oss-security/2020/02/12/3
Related Vulnerabilities
CVE-2023-29020 Vulnerability in npm package @fastify/passport
CVE-2019-12418 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-48631 Vulnerability in npm package @adobe/css-tools
CVE-2022-37616 Vulnerability in npm package @xmldom/xmldom
CVE-2018-1000188 Vulnerability in maven package org.jenkins-ci.plugins:cas-plugin