QID 983813

QID 983813: Java (maven) Security Update for org.jenkins-ci.plugins:kubernetes-cli (GHSA-xrg9-wwrq-xmx9)

Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to refer to GHSA-xrg9-wwrq-xmx9 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 983813

    Software Advisories
    Advisory ID Software Component Link
    GHSA-xrg9-wwrq-xmx9 org.jenkins-ci.plugins:kubernetes-cli URL Logo github.com/advisories/GHSA-xrg9-wwrq-xmx9