CVE-2023-24425: Jenkins Kubernetes Credentials Provider

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.

Affected products

  • Jenkins Kubernetes Credentials Provider: up to and including 1.208.v128ee9800c04

Published 2023-01-26. Last modified 2026-06-17.