VYPR
Medium severity6.5NVD Advisory· Published Jan 26, 2023· Updated Jun 17, 2026

CVE-2023-24425

CVE-2023-24425

Description

Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.cloudbees.jenkins.plugins:kubernetes-credentials-providerMaven
< 1.209.v862c6e5fb1.209.v862c6e5fb

Affected products

3

Patches

Vulnerability mechanics

References

4

News mentions

1