{"id":"GHSA-2jpx-h8j2-g8m4","summary":"Exposure of system-scoped Kubernetes credentials in Jenkins Kubernetes Credentials Provider Plugin","details":"Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.","aliases":["CVE-2023-24425"],"modified":"2025-04-02T22:53:05.715281Z","published":"2023-01-26T21:30:18Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-01-27T01:02:39Z","nvd_published_at":"2023-01-26T21:18:00Z","cwe_ids":["CWE-284"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-24425"},{"type":"WEB","url":"https://github.com/jenkinsci/kubernetes-credentials-provider-plugin/commit/862c6e5fb1ef65968ebfa399239cbef4fff7afc6"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-3022"}],"affected":[{"package":{"name":"com.cloudbees.jenkins.plugins:kubernetes-credentials-provider","ecosystem":"Maven","purl":"pkg:maven/com.cloudbees.jenkins.plugins/kubernetes-credentials-provider"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.209.v862c6e5fb"}]}],"versions":["0.10","0.11","0.12","0.12.1","0.13","0.14","0.15","0.16","0.17","0.18-1","0.20","0.21","0.22","0.8","0.9","1.196.va_55f5e31e3c2","1.199.v4a_1d1f5d074f","1.201.v11b_14c7a_0772","1.206.v7ce2cf7b_0c8b","1.208.v128ee9800c04"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-2jpx-h8j2-g8m4/GHSA-2jpx-h8j2-g8m4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}