CVE-2022-25186
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/02/2022
Last modified:
15/11/2023
Description
Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:jenkins:hashicorp_vault:*:*:*:*:*:jenkins:*:* | 3.8.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



