Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2522%20%281%29 | vendor advisory |
http://www.openwall.com/lists/oss-security/2022/01/12/6 | third party advisory mailing list |