VYPR
High severityNVD Advisory· Published Mar 15, 2022· Updated Oct 15, 2024

CVE-2022-27211

CVE-2022-27211

Description

Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier lacks a permission check, enabling attackers with Overall/Read to connect to an attacker-specified SSH server and capture stored credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier lacks a permission check, enabling attackers with Overall/Read to connect to an attacker-specified SSH server and capture stored credentials.

Vulnerability

Jenkins Kubernetes Continuous Deploy Plugin versions 2.3.1 and earlier contain a missing permission check vulnerability. The plugin allows users with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, thereby capturing credentials stored in Jenkins. [1][2]

Exploitation

An attacker must have Overall/Read permission on the Jenkins instance. The attacker must also obtain valid credentials IDs through a separate vulnerability or method. The attacker can then configure the plugin to connect to an attacker-controlled SSH server, and the plugin will supply credentials associated with those IDs, allowing the attacker to capture them. [1]

Impact

Successful exploitation enables the attacker to capture credentials stored in Jenkins, including potentially sensitive secrets. This could lead to further compromise of Jenkins and its connected systems. [1]

Mitigation

As of the advisory date (2022-03-15), no fix was available for the Kubernetes Continuous Deploy Plugin. The plugin's distribution was suspended on 23 Aug 2022 due to an unresolved remote code execution vulnerability. Users should ensure that only trusted users have Overall/Read permission and consider removing or disabling the plugin if not needed. [3]

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:kubernetes-cdMaven
<= 2.3.1

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

1