CVE-2020-2158 describes a remote code execution vulnerability in Jenkins Literate Plugin 1.0 and earlier. The flaw stems from the plugin's YAML parser not preventing the instantiation of arbitrary types, allowing an authenticated attacker to execute arbitrary code. This high-severity vulnerability (CVSS 8.8) carries a significant risk of complete compromise (C,I,A:H) with low attack complexity. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential impact warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0CPE matchmatch criteria | cpe:2.3:a:jenkins:literate:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.