CVE-2022-23116

HIGH

Jenkins Conjur Secrets < 1.0.9 - Missing Encryption

Title source: rule
STIX 2.1

Description

Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.

Scores

CVSS v3 7.5
EPSS 0.0004
EPSS Percentile 10.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-311
Status published
Products (2)
jenkins/conjur_secrets < 1.0.9
org.conjur.jenkins/conjur-credentials 0 - 1.0.10Maven
Published Jan 12, 2022
Tracked Since Feb 18, 2026