CVE-2022-36888

Severity
6.5MEDIUM
EPSS
0.4%
top 39.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateJul 28

Description

A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5jenkins_project/jenkins_hashicorp_vault_pluginunspecified354.vdb_858fd6b_f48
NVDjenkins/hashicorp_vault354.vdb_858fd6b_f48

🔴Vulnerability Details

3
GHSA
Jenkins HashiCorp Vault Plugin does not perform permission checks in several HTTP endpoints that perform Vault connection tests2022-07-28
OSV
Jenkins HashiCorp Vault Plugin does not perform permission checks in several HTTP endpoints that perform Vault connection tests2022-07-28
CVEList
CVE-2022-36888: A missing permission check in Jenkins HashiCorp Vault Plugin 3542022-07-27

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2022-07-272022-07-27
CVE-2022-36888 (MEDIUM CVSS 6.5) | A missing permission check in Jenki | cvebase.io