CVE-2022-25186
Description
Jenkins HashiCorp Vault Plugin 3.8.0 and earlier allows agents to retrieve arbitrary Vault secrets, enabling attackers with agent control to exfiltrate secrets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins HashiCorp Vault Plugin 3.8.0 and earlier allows agents to retrieve arbitrary Vault secrets, enabling attackers with agent control to exfiltrate secrets.
Vulnerability
Jenkins HashiCorp Vault Plugin versions 3.8.0 and earlier implement functionality that allows agent processes to retrieve Vault secrets for use on the agent. The plugin does not restrict which secrets can be retrieved; an attacker who controls an agent process can specify any Vault path and key to obtain secrets. Affected versions are 3.8.0 and earlier. [1][3]
Exploitation
An attacker needs to be able to control an agent process, for example by having Job/Configure permission or by exploiting another vulnerability that grants agent control. The attacker can then use the plugin's agent-side functionality to request Vault secrets for an arbitrary path and key, without proper authorization checks. [1]
Impact
Successful exploitation allows the attacker to obtain any Vault secrets that the Jenkins controller's Vault token has access to. This can lead to disclosure of sensitive credentials, tokens, or other secrets stored in Vault, potentially enabling further compromise. [1][3]
Mitigation
Jenkins has released HashiCorp Vault Plugin version 3.9.0 which fixes this issue. Users should upgrade to 3.9.0 or later. No workaround is mentioned. The plugin is not listed on the CISA KEV. [1]
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.datapipe.jenkins.plugins:hashicorp-vault-pluginMaven | < 336.v182c0fbaaeb7 | 336.v182c0fbaaeb7 |
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-fm6q-97gw-c4whghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25186ghsaADVISORY
- www.jenkins.io/security/advisory/2022-02-15/ghsax_refsource_CONFIRMWEB
News mentions
1- Jenkins Security Advisory 2022-02-15Jenkins Security Advisories · Feb 15, 2022