{"id":"GHSA-3fm2-hx3h-xm4v","summary":"Jenkins HashiCorp Vault Plugin exposes system-scoped Vault credentials","details":"Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.","aliases":["CVE-2025-67642"],"modified":"2025-12-10T20:41:14.479649Z","published":"2025-12-10T18:30:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-12-10T20:18:21Z","nvd_published_at":"2025-12-10T17:15:56Z","cwe_ids":["CWE-282"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67642"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/hashicorp-vault-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2025-12-10/#SECURITY-3045"}],"affected":[{"package":{"name":"com.datapipe.jenkins.plugins:hashicorp-vault-plugin","ecosystem":"Maven","purl":"pkg:maven/com.datapipe.jenkins.plugins/hashicorp-vault-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"371"}]}],"versions":["1.0","1.1","1.2","1.3","1.4","2.0.0","2.0.1","2.1.0","2.1.1","2.2.0","2.3.0","2.3.1","2.4.0","2.5.0","3.0.0","3.1.0","3.1.1","3.2.0","3.3.0","3.4.0","3.4.1","3.5.0","3.6.0","3.6.1","3.7.0","3.8.0","336.v182c0fbaaeb7","351.vdb_f83a_1c6a_9d","354.vdb_858fd6b_f48","355.v3b_38d767a_b_a_8","356.ved18810a_b_828","359.v2da_3b_45f17d5","360.v0a_1c04cf807d","361.v44fea_4fc08d9","362.v8dfe4061f29e","363.va_f8c1627db_b_a","364.vf5d54b_3dc313","366.v3b_57135510d6","367.v8a_1ee1cccf3a","368.v48134f694db_f","369.vd49b_f7441a_a_3","370.v946b_53544a_30"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-3fm2-hx3h-xm4v/GHSA-3fm2-hx3h-xm4v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}