CVE-2019-10365
Description
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier wrote a temporary access token to a workspace file, allowing users with Job/Read permission to read it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier wrote a temporary access token to a workspace file, allowing users with Job/Read permission to read it.
Vulnerability
Overview
Jenkins Google Kubernetes Engine Plugin creates temporary files in the project workspace during operation. In versions 0.6.2 and earlier, these files contained a short-lived access token used for authentication to Google Kubernetes Engine [1][3]. The token was not stored with proper access controls, relying instead on the default workspace permissions.
Attack
Vector
An attacker authenticated to Jenkins with at least Job/Read permission could access the workspace files of a project that uses the plugin [1]. Because the temporary file resided in the same location as other build artifacts, any user authorized to view the project's workspace could retrieve the token. No additional privileges or cross-site request forgery are required [1][2].
Impact
With the leaked access token, an attacker could impersonate the Jenkins service account for Google Kubernetes Engine. This could allow unauthorized management of GKE clusters, including deploying or modifying workloads, accessing secrets, or escalating privileges within the Kubernetes environment [1].
Mitigation
The Jenkins project released version 0.6.3 of the Google Kubernetes Engine Plugin, which no longer writes the access token to the workspace [2]. All users running versions 0.6.2 or earlier should upgrade immediately. There is no known workaround [1].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:google-kubernetes-engineMaven | < 0.6.3 | 0.6.3 |
Affected products
2- Range: 0.6.2 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-xw4c-9434-3f7pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10365ghsaADVISORY
- www.openwall.com/lists/oss-security/2019/07/31/1ghsamailing-listx_refsource_MLISTWEB
- jenkins.io/security/advisory/2019-07-31/ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.