CVE-2022-27211: High severity kubernetes continuous deploy vulnerability
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27211?
CVE-2022-27211 is a high severity vulnerability due to a missing permission check that allows unauthorized access to sensitive SSH server connections.
How do I fix CVE-2022-27211?
To fix CVE-2022-27211, upgrade the Jenkins Kubernetes Continuous Deploy Plugin to version 2.3.2 or later.
Who is affected by CVE-2022-27211?
CVE-2022-27211 affects users of Jenkins Kubernetes Continuous Deploy Plugin version 2.3.1 and earlier.
What are the potential impacts of CVE-2022-27211?
The potential impacts of CVE-2022-27211 include unauthorized access to Jenkins-stored credentials and the ability to connect to arbitrary SSH servers.
How can attackers exploit CVE-2022-27211?
Attackers can exploit CVE-2022-27211 by leveraging Overall/Read permissions to connect to specified SSH servers using retrieved credential IDs.