Description
A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2102
Related Vulnerabilities
CVE-2020-27216 Vulnerability in maven package jetty:jetty
CVE-2023-32070 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-syntax-html5
CVE-2016-0790 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-17244 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2018-1000195 Vulnerability in maven package org.jenkins-ci.main:jenkins-core