CVE-2022-25186Protection Mechanism Failure in Project Jenkins Hashicorp Vault Plugin

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 77.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateFeb 16

Description

Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin2022-02-16
GHSA
Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin2022-02-16
CVEList
CVE-2022-25186: Jenkins HashiCorp Vault Plugin 32022-02-15

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2022-02-152022-02-15
CVE-2022-25186 — Protection Mechanism Failure | cvebase