First published: Tue Feb 15 2022(Updated: )
Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.datapipe.jenkins.plugins:hashicorp-vault-plugin | <=336.v182c0fbaaeb7 | 351.vdb_f83a_1c6a_9d |
Jenkins Hashicorp Vault | <=336.v182c0fbaaeb7 | |
<=336.v182c0fbaaeb7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.