CVE-2020-2307: Infoleak
Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
Other sources
Jenkins Kubernetes Plugin prior to 1.27.4, 1.26.5, 1.25.4.1, and 1.21.6 includes a feature to replace placeholders in pod template and container template fields with environment variable values.
This feature allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
Kubernetes Plugin 1.27.4, 1.26.5, 1.25.4.1, and 1.21.6 disables this feature.
Kubernetes Plugin 1.27.3 and earlier includes a feature to replace placeholders in pod template and container template fields with environment variable values.
This feature allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-2307?
CVE-2020-2307 has a medium severity rating as it allows low-privilege users to access sensitive Jenkins controller environment variables.
How do I fix CVE-2020-2307?
The fix for CVE-2020-2307 involves upgrading the Jenkins Kubernetes Plugin to version 1.27.4 or later.
What versions of Jenkins are affected by CVE-2020-2307?
Jenkins Kubernetes Plugin versions 1.27.3 and earlier are affected by CVE-2020-2307.
Is my Jenkins installation vulnerable to CVE-2020-2307?
If you are using Jenkins Kubernetes Plugin version 1.27.3 or earlier, your installation is vulnerable to CVE-2020-2307.
What is the impact of CVE-2020-2307?
The impact of CVE-2020-2307 is that it can potentially expose sensitive environment variables to low-privilege users.