CVE-2022-23116

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
12/01/2022
Last modified:
30/11/2023

Description

Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:conjur_secrets:*:*:*:*:*:jenkins:*:* 1.0.9 (including)