Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2022-02-15T16:11:11

Updated: 2024-08-03T04:36:06.418Z

Reserved: 2022-02-15T00:00:00

Link: CVE-2022-25186

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-15T17:15:09.410

Modified: 2024-11-21T06:51:46.277

Link: CVE-2022-25186

cve-icon Redhat

No data.