Description
A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2102
Related Vulnerabilities
CVE-2020-16023 Vulnerability in npm package electron
CVE-2022-41966 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2018-1000608 Vulnerability in maven package org.jenkins-ci.plugins:zos-connector
CVE-2021-23265 Vulnerability in maven package org.craftercms:crafter-core
CVE-2022-28150 Vulnerability in maven package com.synopsys.jenkinsci:ownership