CVE-2020-2308: Medium severity jenkins kubernetes ci vulnerability
A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.
Other sources
Jenkins Kubernetes Plugin prior to 1.27.4, 1.26.5, 1.25.4.1, and 1.21.6 does not perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to list global pod template names.
Kubernetes Plugin 1.27.4, 1.26.5, 1.25.4.1, and 1.21.6 requires Overall/Administer permission to list global pod template names.
Kubernetes Plugin 1.27.3 and earlier does not perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to list global pod template names.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-2308?
CVE-2020-2308 is a vulnerability in Jenkins Kubernetes Plugin 1.27.3 and earlier that allows attackers with Overall/Read permission to list global pod template names.
What is the severity of CVE-2020-2308?
The severity of CVE-2020-2308 is medium with a severity value of 4.
How can I fix CVE-2020-2308?
To fix CVE-2020-2308, you should update Jenkins Kubernetes Plugin to version 1.27.4 or later.
Where can I find more information about CVE-2020-2308?
You can find more information about CVE-2020-2308 at the following references: [Jenkins Security Advisory](https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2102), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:0038), [Red Hat CVE-2020-2308](https://access.redhat.com/security/cve/cve-2020-2308).