CVE-2020-2189: Jenkins Source Code Management Filter Jervis

High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.

Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

Affected products

  • Jenkins Source Code Management Filter Jervis: up to and including 0.2.1

Published 2020-05-06. Last modified 2026-06-17.