A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.datapipe.jenkins.plugins:hashicorp-vault-plugin(Maven) | 0 | 355.v3b_38d767a_b_a_8 | N/A |
CVSS Metrics