VYPR
Low severityNVD Advisory· Published Feb 15, 2022· Updated Aug 3, 2024

CVE-2022-25186

CVE-2022-25186

Description

Jenkins HashiCorp Vault Plugin 3.8.0 and earlier allows agents to retrieve arbitrary Vault secrets, enabling attackers with agent control to exfiltrate secrets.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Jenkins HashiCorp Vault Plugin 3.8.0 and earlier allows agents to retrieve arbitrary Vault secrets, enabling attackers with agent control to exfiltrate secrets.

Vulnerability

Jenkins HashiCorp Vault Plugin versions 3.8.0 and earlier implement functionality that allows agent processes to retrieve Vault secrets for use on the agent. The plugin does not restrict which secrets can be retrieved; an attacker who controls an agent process can specify any Vault path and key to obtain secrets. Affected versions are 3.8.0 and earlier. [1][3]

Exploitation

An attacker needs to be able to control an agent process, for example by having Job/Configure permission or by exploiting another vulnerability that grants agent control. The attacker can then use the plugin's agent-side functionality to request Vault secrets for an arbitrary path and key, without proper authorization checks. [1]

Impact

Successful exploitation allows the attacker to obtain any Vault secrets that the Jenkins controller's Vault token has access to. This can lead to disclosure of sensitive credentials, tokens, or other secrets stored in Vault, potentially enabling further compromise. [1][3]

Mitigation

Jenkins has released HashiCorp Vault Plugin version 3.9.0 which fixes this issue. Users should upgrade to 3.9.0 or later. No workaround is mentioned. The plugin is not listed on the CISA KEV. [1]

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.datapipe.jenkins.plugins:hashicorp-vault-pluginMaven
< 336.v182c0fbaaeb7336.v182c0fbaaeb7

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

1