Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2022/05/17/8 | Mailing List Third Party Advisory |
https://www.jenkins.io/security/advisory/2022-05-17/#SECURITY-2604 | Vendor Advisory |
Configurations
Information
Published : 2022-05-17 08:15
Updated : 2022-05-26 08:32
NVD link : CVE-2022-30951
Mitre link : CVE-2022-30951
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
jenkins
- wmi_windows_agents