Description
Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-1646
Related Vulnerabilities
CVE-2023-46589 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2021-45457 Vulnerability in maven package org.apache.kylin:kylin-server
CVE-2022-24785 Vulnerability in maven package org.webjars.npm:moment
CVE-2023-0868 Vulnerability in maven package org.opennms:opennms-webapp
CVE-2020-17523 Vulnerability in maven package org.apache.shiro:shiro-web