First published: Wed Jan 12 2022(Updated: )
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Conjur Secrets | <=1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23116 has been rated as critical due to its potential for exposing sensitive secrets stored in Jenkins.
To mitigate CVE-2022-23116, upgrade the Jenkins Conjur Secrets Plugin to version 1.0.10 or later.
CVE-2022-23116 affects Jenkins Conjur Secrets Plugin versions 1.0.9 and earlier.
Organizations using affected versions of the Jenkins Conjur Secrets Plugin may be impacted if attackers gain control of agent processes.
CVE-2022-23116 allows attackers controlling agent processes to decrypt secrets stored within Jenkins.