CVE-2023-24425

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-24425
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24425.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-24425
Aliases
Published
2023-01-26T21:18:16Z
Modified
2024-09-03T04:23:48.589871Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.

References

Affected packages

Git / github.com/jenkinsci/kubernetes-credentials-provider-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/kubernetes-credentials-provider-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

1.*

1.196.va_55f5e31e3c2
1.199.v4a_1d1f5d074f
1.201.v11b_14c7a_0772
1.206.v7ce2cf7b_0c8b
1.208.v128ee9800c04

kubernetes-credentials-provider-0.*

kubernetes-credentials-provider-0.10
kubernetes-credentials-provider-0.11
kubernetes-credentials-provider-0.12.1
kubernetes-credentials-provider-0.13
kubernetes-credentials-provider-0.14
kubernetes-credentials-provider-0.15
kubernetes-credentials-provider-0.16
kubernetes-credentials-provider-0.17
kubernetes-credentials-provider-0.18
kubernetes-credentials-provider-0.18-1
kubernetes-credentials-provider-0.19
kubernetes-credentials-provider-0.20
kubernetes-credentials-provider-0.21
kubernetes-credentials-provider-0.22
kubernetes-credentials-provider-0.8
kubernetes-credentials-provider-0.9