CVE-2023-24425

Source
https://cve.org/CVERecord?id=CVE-2023-24425
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24425.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-24425
Aliases
Published
2023-01-26T21:18:16.843Z
Modified
2026-04-10T04:55:51.432661Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.

References

Affected packages

Git / github.com/jenkinsci/kubernetes-credentials-provider-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/kubernetes-credentials-provider-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.208.v128ee9800c04"
        }
    ]
}

Affected versions

1.*
1.196.va_55f5e31e3c2
1.199.v4a_1d1f5d074f
1.201.v11b_14c7a_0772
1.206.v7ce2cf7b_0c8b
1.208.v128ee9800c04
kubernetes-credentials-provider-0.*
kubernetes-credentials-provider-0.10
kubernetes-credentials-provider-0.11
kubernetes-credentials-provider-0.12.1
kubernetes-credentials-provider-0.13
kubernetes-credentials-provider-0.14
kubernetes-credentials-provider-0.15
kubernetes-credentials-provider-0.16
kubernetes-credentials-provider-0.17
kubernetes-credentials-provider-0.18
kubernetes-credentials-provider-0.18-1
kubernetes-credentials-provider-0.19
kubernetes-credentials-provider-0.20
kubernetes-credentials-provider-0.21
kubernetes-credentials-provider-0.22
kubernetes-credentials-provider-0.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24425.json"