Description
Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.
Remediation
References
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2429
Related Vulnerabilities
CVE-2023-26105 Vulnerability in npm package utilities
CVE-2020-1727 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2022-43435 Vulnerability in maven package org.jenkins-ci.plugins.plugin:fireline
CVE-2019-8331 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap
CVE-2023-25767 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials