Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2522%20%282%29 | vendor advisory |
http://www.openwall.com/lists/oss-security/2022/01/12/6 | third party advisory mailing list |