Jenkins JX Resources Plugin Allows Improper Connection to Kubernetes Server
CVE-2019-10339
8.8HIGH
What is CVE-2019-10339?
In the Jenkins JX Resources Plugin, a vulnerability exists due to a missing permission check in the GlobalPluginConfiguration#doValidateClient method. This flaw permits users with Overall/Read access to initiate connections to a Kubernetes server specified by an attacker, potentially leading to the unintended exposure of sensitive credentials. This vulnerability underscores the importance of implementing stringent access controls in plugin configurations to prevent unauthorized access and data breaches.
Affected Version(s)
Jenkins JX Resources Plugin 1.0.36 and earlier