Description
Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
Remediation
References
https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1738
http://www.openwall.com/lists/oss-security/2020/07/02/7
Related Vulnerabilities
CVE-2022-38648 Vulnerability in maven package org.apache.xmlgraphics:batik-bridge
CVE-2022-23710 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2023-26158 Vulnerability in maven package org.webjars.npm:mockjs
CVE-2017-1000398 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-1724 Vulnerability in maven package org.keycloak:keycloak-services