cbcvebase.
CVE-2025-67642
published 2025-12-10

CVE-2025-67642: Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with…

PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.20%
10.3th percentile
Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.

Affected

10 ranges
VendorProductVersion rangeFixed in
jenkinsblazemeter_plugin
jenkinscoverage_plugin
jenkinsgit_client_plugin
jenkinshashicorp_vault<= 371.v884a_4dd60fb_6
jenkinshashicorp_vault_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinsredpen_pipeline_reporter_for_jira_plugin
jenkins_projectjenkins_hashicorp_vault_plugin<= 371.v884a_4dd60fb_6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.