CVE-2022-27209
Description
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CWE
- (none)
Affected
- Jenkins project / Jenkins Kubernetes Continuous Deploy Plugin — v=unspecified ≤2.3.1 [affected]; v=next of 2.3.1 <unspecified [unknown]
CVSS
- (none)
References
- https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-2636 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2022/03/15/2 mailing-list, x_refsource_MLIST
Source
cvelistV5-main/cves/2022/27xxx/CVE-2022-27209.json