Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.
References
Link Resource
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2429 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jenkins

Published: 2022-02-15T16:11:11

Updated: 2023-10-24T14:19:45.224Z

Reserved: 2022-02-15T00:00:00


Link: CVE-2022-25186

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-15T17:15:09.410

Modified: 2023-11-15T03:39:13.003


Link: CVE-2022-25186

JSON object: View

cve-icon Redhat Information

No data.