CVE-2020-2121: Jenkins Google Kubernetes Engine

High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.

Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

Affected products

  • Jenkins Google Kubernetes Engine: up to and including 0.8.0

Published 2020-02-12. Last modified 2026-06-17.