Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-16722
HistoryFeb 17, 2022 - 12:00 a.m.

Jenkins HashiCorp Vault Plugin信息泄露漏洞

2022-02-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.001 Low

EPSS

Percentile

28.4%

Jenkins is a Jenkins open source application. An open source automation server, Jenkins provides hundreds of plugins to support building, deploying, and automating any project.Jenkins HashiCorp Vault Plugin 3.8.0 and earlier versions are vulnerable to an information disclosure vulnerability that stems from the plugin’s implementation of a feature that allows the agent process to retrieve any Vault secret for use on the agent. An attacker could exploit the vulnerability by taking control of the agent process to obtain specified paths and keys.

CPENameOperatorVersion
jenkins hashicorp vault pluginle3.8.0

0.001 Low

EPSS

Percentile

28.4%