Описание
Jenkins Kubernetes CI/CD Plugin vulnerable to Credential Enumeration
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
Note: Jenkins has suspended distribution of this plugin.
Пакеты
Наименование
com.elasticbox.jenkins-ci.plugins:kubernetes-ci
maven
Затронутые версииВерсия исправления
<= 1.3
Отсутствует
Связанные уязвимости
CVSS3: 6.5
nvd
больше 6 лет назад
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.