[JENKINS:SECURITY-2429] Agent-to-controller security bypass in `hashicorp-vault-plugin`
Severity
Low
Affected Packages
2
Fixed Packages
2
CVEs
1
hashicorp-vault-plugin
3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent.
This allows attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.
The functionality that allow agent processes to capture Vault secret can no longer be used in hashicorp-vault-plugin
336.v182c0fbaaeb7.
Package | Affected Version |
---|---|
pkg:maven/org.jenkins-ci.plugins/hashicorp-vault-plugin | <= 3.8.0 |
pkg:github/jenkinsci/hashicorp-vault-plugin-plugin | <= 3.8.0 |
Package | Fixed Version |
---|---|
pkg:maven/org.jenkins-ci.plugins/hashicorp-vault-plugin | = 336.v182c0fbaaeb7 |
pkg:github/jenkinsci/hashicorp-vault-plugin-plugin | = 336.v182c0fbaaeb7 |
- ID
- JENKINS:SECURITY-2429
- Severity
- low
- Published
-
2022-02-15T00:00:00
(2 years ago) - Modified
-
2022-02-15T00:00:00
(2 years ago) - Rights
- Jenkins Security Team
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
Plugin repository | hashicorp-vault-plugin repository | https://github.com/jenkinsci/hashicorp-vault-plugin-plugin |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:maven/org.jenkins-ci.plugins/hashicorp-vault-plugin | org.jenkins-ci.plugins | hashicorp-vault-plugin | <= 3.8.0 | |||
Fixed | pkg:maven/org.jenkins-ci.plugins/hashicorp-vault-plugin | org.jenkins-ci.plugins | hashicorp-vault-plugin | = 336.v182c0fbaaeb7 | |||
Affected | pkg:github/jenkinsci/hashicorp-vault-plugin-plugin | jenkinsci | hashicorp-vault-plugin-plugin | <= 3.8.0 | |||
Fixed | pkg:github/jenkinsci/hashicorp-vault-plugin-plugin | jenkinsci | hashicorp-vault-plugin-plugin | = 336.v182c0fbaaeb7 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |