Junglewise Threat Intelligence

CVE-2022-23117: Agent-to-controller security bypass in Jenkins Conjur Secrets Plugin allows retrieving all credentials

CVE-2022-23117 · Severity: low · CVSS 3.1 · Published 2022-01-13

Technologies: org.conjur.jenkins:conjur-credentials (Maven). Vendors: Maven.

Executive brief

Agent-to-controller security bypass in Jenkins Conjur Secrets Plugin allows retrieving all credentials

Affected products

  • Maven org.conjur.jenkins:conjur-credentials

Related threats