VDB

CVE-2020-2167

CVE-2020-2167 PUBLISHED CVSS 6.5 MEDIUM

Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

EPSS 2.08% · 79.7th percentile

Risk Scores

CVSS 2.0
6.5
EPSS Score
2.08%
79.7th percentile

Affected Products

VendorProductVersions
jenkinsopenshift_pipeline0
Mavencom.openshift.jenkins:openshift-pipeline0
Jenkins projectJenkins OpenShift Pipeline Plugin*

Timeline

  • Mar 25, 2020 CVE Published
  • Mar 30, 2020 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›