Hashicorp Vault Jenkins Hashicorp Vault

Do you want an email whenever new security vulnerabilities are reported in Jenkins Hashicorp Vault?

By the Year

In 2024 there have been 0 vulnerabilities in Jenkins Hashicorp Vault . Last year Hashicorp Vault had 1 security vulnerability published. Right now, Hashicorp Vault is on track to have less security vulnerabilities in 2024 than it did last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 1 7.50
2022 4 6.50
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Hashicorp Vault vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Jenkins Hashicorp Vault Security Vulnerabilities

Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e

CVE-2023-33001 7.5 - High - May 16, 2023

Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

Insertion of Sensitive Information into Log File

A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier

CVE-2022-36888 6.5 - Medium - July 27, 2022

A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.

AuthZ

Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality

CVE-2022-25197 6.5 - Medium - February 15, 2022

Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.

Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality

CVE-2022-25186 6.5 - Medium - February 15, 2022

Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.

Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.

CVE-2022-23109 6.5 - Medium - January 12, 2022

Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.

Insufficiently Protected Credentials

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Jenkins Hashicorp Vault or by Jenkins? Click the Watch button to subscribe.

Jenkins
Vendor

subscribe