CVE-2022-23116: Jenkins Conjur Secrets

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.

Affected products

  • Jenkins Conjur Secrets: up to and including 1.0.9

Published 2022-01-12. Last modified 2026-06-17.