First published: Wed Jan 12 2022(Updated: )
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Conjur Secrets | <=1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23117 has been assigned a high severity rating due to the risk of credential exposure.
To fix CVE-2022-23117, upgrade the Jenkins Conjur Secrets Plugin to version 1.0.10 or later.
Versions 1.0.9 and earlier of the Jenkins Conjur Secrets Plugin are affected by CVE-2022-23117.
CVE-2022-23117 allows attackers who control agent processes to retrieve all stored username/password credentials from the Jenkins controller.
There are no known workarounds for CVE-2022-23117, so it is essential to upgrade the plugin.