Executive brief
Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin allows reading arbitrary files
Affected products
- Maven com.datapipe.jenkins.plugins:hashicorp-vault-plugin
Junglewise Threat Intelligence
CVE-2022-25197 · Severity: low · CVSS 3.1 · Published 2022-02-16
Technologies: com.datapipe.jenkins.plugins:hashicorp-vault-plugin (Maven). Vendors: Maven.
Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin allows reading arbitrary files