Known vulnerabilities in HashiCorp Vault
Vendor:
Jenkins
Software:
HashiCorp Vault
Software CPE:
cpe:2.3:a:jenkins:hashicorp_vault:*:*:*:*:*:*:*:*
Website:
https://jenkins.io/
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
6.1
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU119859 - Improper Ownership Management CVE-2025-67642 |
CWE-282 | Medium | - | 11.12.2025 |
SB2025121128 |
||
| #VU76403 - Credentials Management CVE-2023-33001 |
CWE-255 | Low | - | 22.05.2023 |
SB2023052210 |
||
| #VU65856 - Missing Authorization CVE-2022-36888 |
CWE-862 | Low | 355.v3b_38d767a_b_a_8 | 28.07.2022 |
SB2022072826 |
||
| #VU60647 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-25197 |
CWE-22 | Medium | - | 16.02.2022 |
SB2022021612 |
||
| #VU60646 - Exposure of sensitive information to an unauthorized actor CVE-2022-25186 |
CWE-200 | Low | 336.v182c0fbaaeb7 | 16.02.2022 |
SB2022021611 |
||
| #VU59603 - Exposure of sensitive information to an unauthorized actor CVE-2022-23109 |
CWE-200 | Low | 3.8.0 | 14.01.2022 |
SB2022011405 |