Jenkins HashiCorp Vault Plugin 3.8.0 and previous versions implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jenkins hashicorp vault |