CVE-2025-67642

Dec. 10, 2025, 6:16 p.m.

4.3
Medium

Description

Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.

Product(s) Impacted

Vendor Product Versions
Jenkins
  • Hashicorp Vault Plugin
  • 371.v884a_4dd60fb_6

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-282
Improper Ownership Management
The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a jenkins hashicorp_vault_plugin 371.v884a_4dd60fb_6 / / / / / / /

CVSS Score

4.3 / 10

CVSS Data - 3.1

  • Attack Vector: NETWORK
  • Attack Complexity: LOW
  • Privileges Required: LOW
  • Scope: UNCHANGED
  • Confidentiality Impact: LOW
  • Integrity Impact: NONE
  • Availability Impact: NONE
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

    View Vector String

Timeline

Published: Dec. 10, 2025, 5:15 p.m.
Last Modified: Dec. 10, 2025, 6:16 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

jenkinsci-cert@googlegroups.com

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.