Description
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0598 | Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method. |
Github GHSA |
GHSA-g7fx-mmjc-r7gv | Agent-to-controller security bypass in Jenkins Conjur Secrets Plugin allows decrypting secrets |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T03:36:19.213Z
Reserved: 2022-01-11T00:00:00.000Z
Link: CVE-2022-23116
No data.
Status : Modified
Published: 2022-01-12T20:15:09.707
Modified: 2024-11-21T06:48:01.610
Link: CVE-2022-23116
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA