GHSA-2jpx-h8j2-g8m4
MODERATECVE-2023-24425Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.
- Affected
- < 1.209.v862c6e5fb
- Fixed in
- 1.209.v862c6e5fb
- Weakness
- CWE-284
- Published
- 2023-01-26
- Source
- github