A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.
| Software | From | Fixed in |
|---|---|---|
| jenkins / hashicorp_vault | - | 354.vdb_858fd6b_f48.x |
com.datapipe.jenkins.plugins / hashicorp-vault-plugin
|
- | 355.v3b_38d767a_b_a_8 |