
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67642 is a credential exposure vulnerability in the Jenkins HashiCorp Vault Plugin, tracked as SECURITY-3045, that allows authenticated attackers with Item/Configure permission to access and potentially capture system-scoped Vault credentials they are not authorized to use. It affects HashiCorp Vault Plugin versions 371.v884a_4dd60fb_6 and earlier for Jenkins. The vulnerability was disclosed on December 10, 2025, as part of the Jenkins Security Advisory 2025-12-10. It carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, GitHub Advisory).
The root cause is classified as CWE-282 (Improper Ownership Management): the plugin fails to set the appropriate context when performing Vault credentials lookups, inadvertently allowing access to System-scoped credentials that are normally reserved exclusively for global Jenkins configuration (Jenkins Advisory). An attacker with Item/Configure permission — a relatively low privilege level in Jenkins — can configure a job to reference system-scoped Vault credentials and then trigger a build or credential binding to capture those secrets. No special preconditions beyond holding Item/Configure permission are required, and no user interaction is needed (GitHub Advisory). No public proof-of-concept code has been identified at the time of this report.
Successful exploitation allows a low-privileged Jenkins user to read Vault credentials scoped to the system level, which may include secrets used for global integrations such as infrastructure access tokens, service account credentials, or API keys stored in HashiCorp Vault. This confidentiality breach could enable lateral movement to backend systems protected by those credentials, potentially expanding an attacker's foothold well beyond the Jenkins environment. Integrity and availability are not directly impacted by this vulnerability (Jenkins Advisory, GitHub Advisory).
As of the publication of the Jenkins Security Advisory on December 10, 2025, no patch is available for the HashiCorp Vault Plugin (Jenkins Advisory). Administrators should apply the following mitigations until a fix is released:
The vulnerability was reported by Paul Walker of Ascension Health and disclosed by the Jenkins project as part of a broader December 10, 2025 security advisory covering multiple Jenkins components (Jenkins Advisory). Security news outlet SecurityOnline.info covered the broader Jenkins advisory, noting the range of vulnerabilities disclosed (SecurityOnline). The Jenkins project explicitly noted that no fix was available at the time of publication, following their policy of disclosing vulnerabilities even without patches to allow administrators to take protective action.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."