CVE-2022-25197: Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin allows reading arbitrary files
(updated )
Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.
References
Detect and mitigate CVE-2022-25197 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →