CVE-2020-2211: High severity jenkins kubernetes ci vulnerability
Published Jul 2, 2020
·Updated
Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
Affected Software
1 affected component
Jenkins Kubernetes Ci Jenkins<=1.3
Event History
Jul 2, 2020
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-2211?
CVE-2020-2211 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2020-2211?
To fix CVE-2020-2211, upgrade the Jenkins Kubernetes CI/CD Plugin to version 1.4 or later.
3
What types of systems are affected by CVE-2020-2211?
CVE-2020-2211 affects Jenkins installations using the Kubernetes CI/CD Plugin versions 1.3 and earlier.
4
Can CVE-2020-2211 lead to data breaches?
Yes, CVE-2020-2211 can lead to data breaches as it allows remote code execution on affected systems.
5
Is it possible to exploit CVE-2020-2211 remotely?
Yes, CVE-2020-2211 can be exploited remotely if the vulnerable version is deployed.