CVE-2022-27211
Description
Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier lacks a permission check, enabling attackers with Overall/Read to connect to an attacker-specified SSH server and capture stored credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier lacks a permission check, enabling attackers with Overall/Read to connect to an attacker-specified SSH server and capture stored credentials.
Vulnerability
Jenkins Kubernetes Continuous Deploy Plugin versions 2.3.1 and earlier contain a missing permission check vulnerability. The plugin allows users with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, thereby capturing credentials stored in Jenkins. [1][2]
Exploitation
An attacker must have Overall/Read permission on the Jenkins instance. The attacker must also obtain valid credentials IDs through a separate vulnerability or method. The attacker can then configure the plugin to connect to an attacker-controlled SSH server, and the plugin will supply credentials associated with those IDs, allowing the attacker to capture them. [1]
Impact
Successful exploitation enables the attacker to capture credentials stored in Jenkins, including potentially sensitive secrets. This could lead to further compromise of Jenkins and its connected systems. [1]
Mitigation
As of the advisory date (2022-03-15), no fix was available for the Kubernetes Continuous Deploy Plugin. The plugin's distribution was suspended on 23 Aug 2022 due to an unresolved remote code execution vulnerability. Users should ensure that only trusted users have Overall/Read permission and consider removing or disabling the plugin if not needed. [3]
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:kubernetes-cdMaven | <= 2.3.1 | — |
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-794j-hx96-4w3mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-27211ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/03/15/2ghsamailing-listx_refsource_MLISTWEB
- www.jenkins.io/security/advisory/2022-03-15/ghsax_refsource_CONFIRMWEB
News mentions
1- Jenkins Security Advisory 2022-03-15Jenkins Security Advisories · Mar 15, 2022