Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2cm5-f78c-h2c8

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Missing permission checks in Jenkins Distributed Fork Plugin

It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.

Пакеты

Наименование

org.jenkins-ci.plugins:distfork

maven
Затронутые версииВерсия исправления

<= 1.5.0

1.6.0

EPSS

Процентиль: 43%
0.00208
Низкий

8.8 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.8
nvd
около 7 лет назад

It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.

EPSS

Процентиль: 43%
0.00208
Низкий

8.8 High

CVSS3

Дефекты

CWE-287