Lucene search

K
osvGoogleOSV:GHSA-7JF5-P556-75PR
HistoryMay 24, 2022 - 4:59 p.m.

Jenkins Kubernetes CI/CD Plugin vulnerable to Credential Enumeration

2022-05-2416:59:37
Google
osv.dev
6

0.001 Low

EPSS

Percentile

28.4%

A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

Note: Jenkins has suspended distribution of this plugin.

0.001 Low

EPSS

Percentile

28.4%

Related for OSV:GHSA-7JF5-P556-75PR