First published: Wed Jan 12 2022(Updated: )
Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.datapipe.jenkins.plugins:hashicorp-vault-plugin | <3.8.0 | 3.8.0 |
HashiCorp Vault | <=3.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23109 has a high severity level due to the potential exposure of sensitive Vault credentials.
To fix CVE-2022-23109, upgrade the Jenkins HashiCorp Vault Plugin to version 3.8.0 or later.
CVE-2022-23109 affects Jenkins HashiCorp Vault Plugin versions up to and including 3.7.0 when used with Pipeline: Groovy Plugin 2.85 or later.
CVE-2022-23109 allows the exposure of Vault credentials in Pipeline build logs and descriptions.
Yes, upgrading to version 3.8.0 of the Jenkins HashiCorp Vault Plugin mitigates the vulnerability.