GHSA-324h-2v7h-q3xx
HIGHCVE-2020-2179Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types. This results in a remote code execution (RCE) vulnerability exploitable by users able to configure a multi-configuration (Matrix) job, or control the contents of a previously configured job’s SCM repository.
- Affected
- <= 0.2.0
- Fixed in
- 0.2.1
- Weakness
- CWE-502
- Published
- 2022-05-24
- Source
- github