Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kubernetes_credentials_provider | Jenkins | * | 1.208.v128ee9800c04 (including) |