Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hch9-6qrj-5f49

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Jenkins Kubernetes CI/CD Plugin vulnerable to Improper Authorization

A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Note: Jenkins has suspended distribution of this plugin.

Пакеты

Наименование

com.elasticbox.jenkins-ci.plugins:kubernetes-ci

maven
Затронутые версииВерсия исправления

<= 1.3

Отсутствует

EPSS

Процентиль: 15%
0.00048
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-276
CWE-285

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

EPSS

Процентиль: 15%
0.00048
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-276
CWE-285