Jenkins Google Kubernetes Engine Plugin vulnerable to Exposure of Resource to Wrong Sphere
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Oct 26, 2023
Package
Affected versions
< 0.6.3
Patched versions
0.6.3
Description
Published by the National Vulnerability Database
Jul 31, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Mar 3, 2023
Last updated
Oct 26, 2023
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file named
.kube…config
containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.This temporary file is now created outside the regular project workspace.
References