CVE-2019-10445: Jenkins Google Kubernetes Engine

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/Read permission to obtain limited information about the scope of a credential with an attacker-specified credentials ID.

Affected products

  • Jenkins Google Kubernetes Engine: up to and including 0.7.0

Published 2019-10-16. Last modified 2026-06-17.