A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes(Maven) | 1.27.0 | 1.27.4 | N/A |
| org.csanchez.jenkins.plugins:kubernetes(Maven) | 1.26.0 | 1.26.5 | N/A |
| org.csanchez.jenkins.plugins:kubernetes(Maven) | 1.22.0 | 1.25.4.1 | N/A |
| org.csanchez.jenkins.plugins:kubernetes(Maven) | 0 | 1.21.6 | N/A |
CVSS Metrics