GHSA-xqqr-mq8x-22qx
MODERATECVE-2019-10339Jenkins jx-resources Plugin did not perform permission checks on a method implementing form validation. This allowed users with Overall/Read access to Jenkins to connect to an attacker-specified Kubernetes server and obtain information about an attacker-specified namespace. Doing so might also leak service account credentials used for the connection. Additionally, it allowed attackers to obtain th
- Affected
- <= 1.0.36
- Fixed in
- 1.0.37
- Weakness
- CWE-862
- Published
- 2022-05-24
- Source
- github