Lucene search

K
osvGoogleOSV:GHSA-FM6Q-97GW-C4WH
HistoryFeb 16, 2022 - 12:01 a.m.

Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin

2022-02-1600:01:28
Google
osv.dev
13

0.001 Low

EPSS

Percentile

28.4%

Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.

0.001 Low

EPSS

Percentile

28.4%