Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.cloudbees.jenkins.plugins:kubernetes-credentials-provider(Maven) | 0 | 1.209.v862c6e5fb | N/A |
CVSS Metrics