Skip to main content
Vulnerability Database/CVE-2025-67642

CVE-2025-67642: Jenkins Hashicorp Vault Privilege Escalation

CVE-2025-67642 is a privilege escalation vulnerability in Jenkins Hashicorp Vault Plugin that allows unauthorized access to Vault credentials. This article covers technical details, affected versions, and remediation.

Published:

CVE-2025-67642 Overview

CVE-2025-67642 affects the Jenkins HashiCorp Vault Plugin version 371.v884a_4dd60fb_6 and earlier. The plugin does not set the appropriate context for Vault credentials lookup. Attackers with Item/Configure permission can access and potentially capture Vault credentials they are not entitled to use. The weakness is classified under CWE-282: Improper Ownership Management. Jenkins disclosed the issue in security advisory SECURITY-3045 on December 10, 2025.

Critical Impact

Authenticated Jenkins users with job configuration rights can retrieve HashiCorp Vault secrets scoped to other users or folders, breaking credential isolation boundaries.

Affected Products

  • Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier
  • Jenkins controllers configured with HashiCorp Vault credential providers
  • Downstream Jenkins pipelines that reference Vault-managed secrets

Discovery Timeline

  • 2025-12-10 - Jenkins publishes security advisory SECURITY-3045
  • 2025-12-10 - CVE-2025-67642 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-67642

Vulnerability Analysis

The Jenkins HashiCorp Vault Plugin integrates Jenkins credential storage with HashiCorp Vault, allowing pipelines to fetch secrets at build time. Jenkins enforces credential scoping through an authentication context object that determines which credentials a job or user may read. When a plugin looks up a credential, it must pass the correct context so that Jenkins evaluates access against the requesting user, not against elevated system permissions.

The affected plugin performs Vault credential lookups without supplying the appropriate authentication context. As a result, the lookup executes with broader permissions than the requesting user holds. A user with Item/Configure permission on any job can craft a job configuration that references Vault credentials outside their scope. The plugin resolves those identifiers and exposes the underlying secrets to the job runtime.

Root Cause

The root cause is improper ownership management [CWE-282] during credential resolution. The plugin fails to constrain the credential lookup to the current user's authentication object. The lookup uses ACL.SYSTEM or an equivalent elevated context, so Jenkins returns credentials that the user cannot legitimately access.

Attack Vector

An authenticated attacker holding Item/Configure permission edits or creates a job. The job references a Vault credential ID that belongs to a different folder, user, or higher-privileged scope. During build execution, the plugin injects the resolved secret into the build environment, log output, or a controlled sink such as an echo step. The attacker recovers the value from the build artifacts or logs. Exploitation requires low-privilege authentication and no user interaction.

No public proof-of-concept exploit code has been released. See the Jenkins Security Advisory SECURITY-3045 for vendor technical details.

Detection Methods for CVE-2025-67642

Indicators of Compromise

  • Build logs or console output containing Vault secret material or references to credential IDs outside the job's expected scope.
  • Unexpected modifications to job configurations that add Vault credential bindings, especially by users with only Item/Configure rights.
  • HashiCorp Vault audit log entries showing token lookups initiated by the Jenkins service account for paths not tied to the requesting job's folder.

Detection Strategies

  • Inventory installed plugins on all Jenkins controllers and flag any HashiCorp Vault Plugin version at or below 371.v884a_4dd60fb_6.
  • Correlate Jenkins job configuration change events with subsequent Vault read operations to identify anomalous credential references.
  • Review pipeline definitions for withVault or vaultCredential bindings that reference credential IDs not owned by the job's folder.

Monitoring Recommendations

  • Enable Jenkins audit logging and forward events to a centralized SIEM for correlation with Vault audit logs.
  • Alert on new or modified job configurations that add credential bindings, especially by non-administrator users.
  • Monitor Vault audit logs for read operations against secret paths that fall outside a Jenkins job's expected namespace.

How to Mitigate CVE-2025-67642

Immediate Actions Required

  • Upgrade the Jenkins HashiCorp Vault Plugin to a version later than 371.v884a_4dd60fb_6 as published in SECURITY-3045.
  • Audit all Jenkins users with Item/Configure permission and remove the grant from any account that does not require it.
  • Rotate any HashiCorp Vault secrets that were referenced through the plugin during the exposure window.

Patch Information

Jenkins released a fixed version of the HashiCorp Vault Plugin on December 10, 2025, alongside advisory SECURITY-3045. Administrators should apply the update through the Jenkins Plugin Manager and restart the controller. Verify that the running plugin version is greater than 371.v884a_4dd60fb_6 after restart.

Workarounds

  • Restrict Item/Configure and folder-level configure permissions to trusted administrators until the patch is applied.
  • Segment Jenkins controllers so that Vault-integrated jobs run on dedicated instances with tightly scoped user access.
  • Use folder-scoped credential providers and namespace-scoped Vault policies to limit the blast radius of a successful lookup abuse.
bash
# Verify installed plugin version from the Jenkins CLI
java -jar jenkins-cli.jar -s https://jenkins.example.com/ \
  list-plugins | grep -i hashicorp-vault

# Example expected output after patching
# hashicorp-vault  HashiCorp Vault Plugin  <version-greater-than-371.v884a_4dd60fb_6>

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.