Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xw4c-9434-3f7p

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins Google Kubernetes Engine Plugin vulnerable to Exposure of Resource to Wrong Sphere

Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file named .kube…config containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.

This temporary file is now created outside the regular project workspace.

Пакеты

Наименование

org.jenkins-ci.plugins:google-kubernetes-engine

maven
Затронутые версииВерсия исправления

< 0.6.3

0.6.3

EPSS

Процентиль: 26%
0.00086
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 4.3
nvd
около 6 лет назад

Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.

EPSS

Процентиль: 26%
0.00086
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668