Lucene search

K
osvGoogleOSV:GHSA-XW4C-9434-3F7P
HistoryMay 24, 2022 - 4:51 p.m.

Jenkins Google Kubernetes Engine Plugin vulnerable to Exposure of Resource to Wrong Sphere

2022-05-2416:51:51
Google
osv.dev
5

4.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file named .kube…config containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.

This temporary file is now created outside the regular project workspace.

4.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

Related for OSV:GHSA-XW4C-9434-3F7P