GHSA-5qff-7944-vq4f
HIGHCVE-2020-2168Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types. This results in a remote code execution (RCE) vulnerability exploitable by users able to provide YAML input files to Azure Container Service Plugin’s build step.
- Affected
- < 1.0.2
- Fixed in
- 1.0.2
- Published
- 2022-05-24
- Source
- github