[JENKINS:SECURITY-2429] Agent-to-controller security bypass in `hashicorp-vault-plugin`

Severity Low
Affected Packages 2
Fixed Packages 2
CVEs 1

hashicorp-vault-plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent.

This allows attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.

The functionality that allow agent processes to capture Vault secret can no longer be used in hashicorp-vault-plugin 336.v182c0fbaaeb7.

ID
JENKINS:SECURITY-2429
Severity
low
Published
2022-02-15T00:00:00
(2 years ago)
Modified
2022-02-15T00:00:00
(2 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository hashicorp-vault-plugin repository https://github.com/jenkinsci/hashicorp-vault-plugin-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/hashicorp-vault-plugin org.jenkins-ci.plugins hashicorp-vault-plugin <= 3.8.0
Fixed pkg:maven/org.jenkins-ci.plugins/hashicorp-vault-plugin org.jenkins-ci.plugins hashicorp-vault-plugin = 336.v182c0fbaaeb7
Affected pkg:github/jenkinsci/hashicorp-vault-plugin-plugin jenkinsci hashicorp-vault-plugin-plugin <= 3.8.0
Fixed pkg:github/jenkinsci/hashicorp-vault-plugin-plugin jenkinsci hashicorp-vault-plugin-plugin = 336.v182c0fbaaeb7
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...