Количество 2
Количество 2
CVE-2023-24425
Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.
GHSA-2jpx-h8j2-g8m4
Exposure of system-scoped Kubernetes credentials in Jenkins Kubernetes Credentials Provider Plugin
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-24425 Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
GHSA-2jpx-h8j2-g8m4 Exposure of system-scoped Kubernetes credentials in Jenkins Kubernetes Credentials Provider Plugin | CVSS3: 6.5 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу