[JENKINS:SECURITY-2096] Arbitrary file read vulnerability in `kubernetes-cd`

Severity Medium
Affected Packages 2
CVEs 1

kubernetes-cd contributes the 'Kubernetes configuration (kubeconfig)' credential type.

kubernetes-cd 2.3.1 and earlier allows users with Credentials/Create or Credentials/Update permission to read arbitrary files on the Jenkins controller by defining a 'From a file on the Jenkins master' Kubeconfig source for such a credential.

As of publication of this advisory, there is no fix.

ID
JENKINS:SECURITY-2096
Severity
medium
Published
2022-03-15T00:00:00
(2 years ago)
Modified
2022-03-15T00:00:00
(2 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository kubernetes-cd repository https://github.com/jenkinsci/kubernetes-cd-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/kubernetes-cd org.jenkins-ci.plugins kubernetes-cd <= 2.3.1
Affected pkg:github/jenkinsci/kubernetes-cd-plugin jenkinsci kubernetes-cd-plugin <= 2.3.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...