Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and previous versions does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jenkins kubernetes credentials provider |