CVE-2020-2166: Jenkins Pipeline: Aws Steps

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

Affected products

  • Jenkins Pipeline: Aws Steps: up to and including 1.40

Published 2020-03-25. Last modified 2026-06-17.