Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2022/05/17/8 | Mailing List Third Party Advisory |
https://www.jenkins.io/security/advisory/2022-05-17/#SECURITY-2604 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2022/05/17/8 | Mailing List Third Party Advisory |
https://www.jenkins.io/security/advisory/2022-05-17/#SECURITY-2604 | Vendor Advisory |
Configurations
History
21 Nov 2024, 07:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2022/05/17/8 - Mailing List, Third Party Advisory | |
References | () https://www.jenkins.io/security/advisory/2022-05-17/#SECURITY-2604 - Vendor Advisory |
Information
Published : 2022-05-17 15:15
Updated : 2024-11-21 07:03
NVD link : CVE-2022-30951
Mitre link : CVE-2022-30951
CVE.ORG link : CVE-2022-30951
JSON object : View
Products Affected
jenkins
- wmi_windows_agents
CWE
CWE-862
Missing Authorization