Description
Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-1646
Related Vulnerabilities
CVE-2020-2244 Vulnerability in maven package org.jenkins-ci.plugins:build-failure-analyzer
CVE-2021-45456 Vulnerability in maven package org.apache.kylin:kylin-server-base
CVE-2023-25761 Vulnerability in maven package org.jenkins-ci.plugins:junit
CVE-2023-34466 Vulnerability in maven package org.xwiki.platform:xwiki-platform-tag-api
CVE-2020-2217 Vulnerability in maven package org.jenkins-ci.plugins:compatibility-action-storage