Description
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.
Scores
CVSS v3
7.5
EPSS
0.0004
EPSS Percentile
10.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-311
Status
published
Products (2)
jenkins/conjur_secrets
< 1.0.9
org.conjur.jenkins/conjur-credentials
0 - 1.0.10Maven
Published
Jan 12, 2022
Tracked Since
Feb 18, 2026