GHSA-fm6q-97gw-c4wh
GitHub Security Advisory
Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.
Affected Packages
Maven
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
Affected versions:
0
(fixed in 336.v182c0fbaaeb7)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.