The openshift-pipeline Jenkins plugin, as included in OpenShift's jenkins-2-plugins package, is vulnerable to remote code exection via deserializtion of YAML via the bundled SnakeYAML library. Authenticated Jenkins could users exploit this vulnerability to execute arbitrary code on the Jenkins server.