
CVE-2022-27211
https://notcve.org/view.php?id=CVE-2022-27211
15 Mar 2022 — A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. Una comprobación de permisos faltante/incorrecta en el Plugin Kubernetes Continuous Deploy de Jenkins versiones 2.3.1 y anteriores, permite a atacantes con permiso de Overall/Read conectarse a un servidor SSH esp... • http://www.openwall.com/lists/oss-security/2022/03/15/2 • CWE-862: Missing Authorization •

CVE-2022-27210
https://notcve.org/view.php?id=CVE-2022-27210
15 Mar 2022 — A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. Una vulnerabilidad de tipo cross-site request forgery (CSRF) en el Plugin Kubernetes Continuous Deploy de Jenkins versiones 2.3.1 y anteriores, permite a atacantes conectarse a un servidor SSH especificado por el ataca... • http://www.openwall.com/lists/oss-security/2022/03/15/2 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2022-27209
https://notcve.org/view.php?id=CVE-2022-27209
15 Mar 2022 — A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Una falta de comprobación de permisos en el Plugin Kubernetes Continuous Deploy de Jenkins versiones 2.3.1 y anteriores, permite a atacantes con permiso Overall/Read enumerar los IDs de las credenciales almacenadas en Jenkins • http://www.openwall.com/lists/oss-security/2022/03/15/2 • CWE-862: Missing Authorization •

CVE-2022-27208
https://notcve.org/view.php?id=CVE-2022-27208
15 Mar 2022 — Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller. El plugin Kubernetes Continuous Deploy de Jenkins versiones 2.3.1 y anteriores, permite a usuarios con permiso Credentials/Create leer archivos arbitrarios en el controlador Jenkins • http://www.openwall.com/lists/oss-security/2022/03/15/2 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •