A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb858fd6bf48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36888.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "354.vdb_858fd6b_f48" } ] } ]