Vulnerabilities
Vulnerable Software
Jenkins:  >> Conjur Secrets  Security Vulnerabilities
A missing permission check in Jenkins Conjur Secrets Plugin 1.0.11 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVSS Score
4.3
EPSS Score
0.003
Published
2022-02-15
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-01-12
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.
CVSS Score
7.5
EPSS Score
0.006
Published
2022-01-12


Contact Us

Shodan ® - All rights reserved