Junglewise Threat Intelligence

CVE-2022-36888: Jenkins HashiCorp Vault Plugin does not perform permission checks in several HTTP endpoints that perform Vault connection tests

CVE-2022-36888 · Severity: low · CVSS 3.1 · Published 2022-07-28

Technologies: com.datapipe.jenkins.plugins:hashicorp-vault-plugin (Maven). Vendors: Maven.

Executive brief

Jenkins HashiCorp Vault Plugin does not perform permission checks in several HTTP endpoints that perform Vault connection tests

Affected products

  • Maven com.datapipe.jenkins.plugins:hashicorp-vault-plugin

Related threats