GHSA-794j-hx96-4w3m
HIGHCVE-2022-27211A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
- Affected
- <= 2.3.1
- Fixed in
- not stated
- Weakness
- CWE-862
- Published
- 2022-03-16
- Source
- github