Improper authorization control for web services In com.datapipe.jenkins.plugins:hashicorp-vault-plugin
Description
Jenkins HashiCorp Vault Plugin does not perform permission checks in several HTTP endpoints that perform Vault connection tests A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 355.v3b_38d767a_b_a_8 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.