Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jpx-h8j2-g8m4

Опубликовано: 26 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Exposure of system-scoped Kubernetes credentials in Jenkins Kubernetes Credentials Provider Plugin

Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.

Пакеты

Наименование

com.cloudbees.jenkins.plugins:kubernetes-credentials-provider

maven
Затронутые версииВерсия исправления

< 1.209.v862c6e5fb

1.209.v862c6e5fb

EPSS

Процентиль: 70%
0.00653
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
около 3 лет назад

Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.

EPSS

Процентиль: 70%
0.00653
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284