CVE-2025-67642: Medium severity HashiCorp Jenkins HashiCorp Vault Plugin vulnerability
Jenkins HashiCorp Vault Plugin 371.v884a4dd60fb6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67642?
CVE-2025-67642 has been classified as a high severity vulnerability due to its potential to expose sensitive Vault credentials.
How do I fix CVE-2025-67642?
To mitigate CVE-2025-67642, upgrade the Jenkins HashiCorp Vault Plugin to version 372 or later.
Who is affected by CVE-2025-67642?
CVE-2025-67642 affects users of HashiCorp Vault Plugin versions 371.v884a_4dd60fb_6 and earlier.
What types of permissions do attackers need to exploit CVE-2025-67642?
Attackers need Item/Configure permission to exploit CVE-2025-67642 and access Vault credentials.
What impact can CVE-2025-67642 have on my Jenkins environment?
CVE-2025-67642 can potentially allow unauthorized access to sensitive Vault credentials, which may lead to further compromises.