A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.
References
https://nvd.nist.gov/vuln/detail/CVE-2020-2308
https://www.jenkins.io/security/advis…