CVE-2025-67642 Details
Description
Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.
A vulnerability exists in the HashiCorp Vault Plugin for Jenkins, specifically in versions through 371.v884a_4dd60fb_6. The plugin fails to set the correct context for looking up Vault credentials, which allows attackers with Item/Configure permission to access and potentially capture Vault credentials they should not have access to.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2025-12-10/#SECURITY-3045 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-282 | Improper Ownership Management | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins hashicorp vault | <= 371.v884a_4dd60fb_6 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 17, 2025 | Initial Analysis | [email protected] |
| Dec 10, 2025 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | New CVE Received | [email protected] |