Description
Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-1646
Related Vulnerabilities
CVE-2023-2585 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2023-30535 Vulnerability in maven package net.snowflake:snowflake-jdbc
CVE-2019-10407 Vulnerability in maven package hudson.plugins:project-inheritance
CVE-2021-24122 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-23307 Vulnerability in maven package org.apache.logging.log4j:log4j