CVE-2023-24425

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-24425
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24425.json
Aliases
Published
2023-01-26T21:18:16Z
Modified
2023-11-29T09:53:31.695401Z
Details

Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.

References

Affected packages

Git / github.com/jenkinsci/kubernetes-credentials-provider-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/kubernetes-credentials-provider-plugin
Events
Introduced
0The exact introduced commit is unknown
Last affected

Affected versions

1.*

1.196.va_55f5e31e3c2
1.199.v4a_1d1f5d074f
1.201.v11b_14c7a_0772
1.206.v7ce2cf7b_0c8b
1.208.v128ee9800c04

kubernetes-credentials-provider-0.*

kubernetes-credentials-provider-0.10
kubernetes-credentials-provider-0.11
kubernetes-credentials-provider-0.12.1
kubernetes-credentials-provider-0.13
kubernetes-credentials-provider-0.14
kubernetes-credentials-provider-0.15
kubernetes-credentials-provider-0.16
kubernetes-credentials-provider-0.17
kubernetes-credentials-provider-0.18
kubernetes-credentials-provider-0.18-1
kubernetes-credentials-provider-0.19
kubernetes-credentials-provider-0.20
kubernetes-credentials-provider-0.21
kubernetes-credentials-provider-0.22
kubernetes-credentials-provider-0.8
kubernetes-credentials-provider-0.9