CVE-2019-10365: Medium severity google kubernetes engine vulnerability
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.
Other sources
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file named .kube…config containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.
This temporary file is now created outside the regular project workspace.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10365?
CVE-2019-10365 is a vulnerability in Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier that allows users with Job/Read permission to access a temporary file containing a temporary access token.
How severe is CVE-2019-10365?
CVE-2019-10365 has a severity value of 4.3, which is considered medium.
How does CVE-2019-10365 work?
CVE-2019-10365 occurs when the Jenkins Google Kubernetes Engine Plugin creates a temporary file named `.kube...config` containing a temporary access token in the project workspace, allowing users with Job/Read permission to access it.
What software versions are affected by CVE-2019-10365?
Jenkins Google Kubernetes Engine Plugin versions up to and including 0.6.2 are affected by CVE-2019-10365.
How do I fix CVE-2019-10365?
To fix CVE-2019-10365, update your Jenkins Google Kubernetes Engine Plugin to version 0.6.3 or later.