Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-24425


Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.


Published

2023-01-26T21:18:16.843

Last Modified

2025-04-02T15:15:54.820

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins kubernetes_credentials_provider ≤ 1.208.v128ee9800c04 Yes

References