[
  {"cve_id":"CVE-2019-16576","description":"A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kubernetes service account token or credentials stored in Jenkins.","exploit_maturity":"No public exploit","published":"2019-12-17","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Medium"},
  {"cve_id":"CVE-2019-16575","description":"A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kubernetes service account token or credentials stored in Jenkins.","exploit_maturity":"No public exploit","published":"2019-12-17","resolved":"NO-EXPLOIT-PUBLISHED","severity":"High"}
]
