CVE-2025-67642
Java vulnerability analysis and mitigation

Overview

CVE-2025-67642 is a credential exposure vulnerability in the Jenkins HashiCorp Vault Plugin, tracked as SECURITY-3045, that allows authenticated attackers with Item/Configure permission to access and potentially capture system-scoped Vault credentials they are not authorized to use. It affects HashiCorp Vault Plugin versions 371.v884a_4dd60fb_6 and earlier for Jenkins. The vulnerability was disclosed on December 10, 2025, as part of the Jenkins Security Advisory 2025-12-10. It carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-282 (Improper Ownership Management): the plugin fails to set the appropriate context when performing Vault credentials lookups, inadvertently allowing access to System-scoped credentials that are normally reserved exclusively for global Jenkins configuration (Jenkins Advisory). An attacker with Item/Configure permission — a relatively low privilege level in Jenkins — can configure a job to reference system-scoped Vault credentials and then trigger a build or credential binding to capture those secrets. No special preconditions beyond holding Item/Configure permission are required, and no user interaction is needed (GitHub Advisory). No public proof-of-concept code has been identified at the time of this report.

Impact

Successful exploitation allows a low-privileged Jenkins user to read Vault credentials scoped to the system level, which may include secrets used for global integrations such as infrastructure access tokens, service account credentials, or API keys stored in HashiCorp Vault. This confidentiality breach could enable lateral movement to backend systems protected by those credentials, potentially expanding an attacker's foothold well beyond the Jenkins environment. Integrity and availability are not directly impacted by this vulnerability (Jenkins Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Jenkins instance running HashiCorp Vault Plugin version 371.v884a_4dd60fb_6 or earlier. Confirm that the instance integrates with HashiCorp Vault for credential management.
  2. Obtain Item/Configure permission: Log in to Jenkins with an account that has Item/Configure permission on at least one job or pipeline. This may be a standard developer or CI/CD operator account.
  3. Configure a job to reference system-scoped credentials: Using the Jenkins UI or REST API, configure a job to use a Vault credential binding that references a system-scoped Vault credential ID. Because the plugin does not enforce the correct context, the lookup will succeed even though the credential is not intended to be accessible at the item level.
  4. Trigger a build: Execute the configured job. During the build, the Vault credential is resolved and injected into the build environment.
  5. Capture the credential: Extract the secret from build logs (if not masked), environment variable dumps, or by configuring the job to echo or exfiltrate the credential value to an attacker-controlled endpoint (Jenkins Advisory).

Indicators of compromise

  • Logs: Jenkins audit logs showing Item/Configure actions by low-privileged users on jobs that reference Vault credential IDs normally associated with global/system configuration; build logs showing unexpected Vault credential resolution for system-scoped secrets.
  • Jenkins Build History: Jobs configured or modified by users who do not typically manage global credentials, especially if those jobs include Vault credential bindings referencing system-level credential IDs.
  • Network: Outbound connections from the Jenkins controller to attacker-controlled hosts during build execution, potentially carrying exfiltrated credential values.
  • HashiCorp Vault Audit Logs: Vault audit trail entries showing credential access from Jenkins for secrets that should only be accessed by global system processes, particularly if triggered by unexpected job runs or at unusual times (Jenkins Advisory).

Mitigation and workarounds

As of the publication of the Jenkins Security Advisory on December 10, 2025, no patch is available for the HashiCorp Vault Plugin (Jenkins Advisory). Administrators should apply the following mitigations until a fix is released:

  • Restrict Item/Configure permissions: Audit and minimize the number of users granted Item/Configure permission, applying the principle of least privilege.
  • Audit Vault credential scoping: Review which credentials are stored at the System scope in Jenkins and consider moving sensitive secrets to a dedicated secrets management solution with stricter access controls outside of Jenkins.
  • Monitor Vault audit logs: Enable and review HashiCorp Vault audit logs for unexpected access patterns originating from Jenkins.
  • Disable the plugin: If system-scoped Vault credentials are critical and cannot be adequately protected, consider temporarily disabling the HashiCorp Vault Plugin until a fix is available.

Community reactions

The vulnerability was reported by Paul Walker of Ascension Health and disclosed by the Jenkins project as part of a broader December 10, 2025 security advisory covering multiple Jenkins components (Jenkins Advisory). Security news outlet SecurityOnline.info covered the broader Jenkins advisory, noting the range of vulnerabilities disclosed (SecurityOnline). The Jenkins project explicitly noted that no fix was available at the time of publication, following their policy of disclosing vulnerabilities even without patches to allow administrators to take protective action.

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p279-2cqp-84jgCRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesJul 24, 2026
GHSA-fp43-vj7g-pg92HIGH7.5
  • Java logoJava
  • org.omnifaces:omnifaces
NoYesJul 24, 2026
GHSA-7ppr-r889-mcf2HIGH7.5
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.12
NoYesJul 24, 2026
GHSA-mhvj-jhpq-885vHIGH7.4
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.13
NoYesJul 24, 2026
GHSA-46q4-43ph-c6frHIGH7.4
  • Java logoJava
  • org.http4s:blaze-http_2.12
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management