PT-2022-15859 · Jenkins · Jenkins Conjur Secrets Plugin+1

Daniel Beck

·

Published

2022-01-12

·

Updated

2023-11-30

·

CVE-2022-23116

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Conjur Secrets Plugin versions 1.0.9 and earlier
Description The issue allows attackers who can control agent processes to decrypt secrets stored in Jenkins, which were obtained through another method. This is possible due to the implementation of certain functionality in the plugin.
Recommendations For Jenkins Conjur Secrets Plugin versions 1.0.9 and earlier, update to a version later than 1.0.9 to resolve the issue. As a temporary workaround, consider restricting access to agent processes to minimize the risk of exploitation.

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2022-23116
GHSA-G7FX-MMJC-R7GV

Affected Products

Jenkins
Jenkins Conjur Secrets Plugin