It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1967 | It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes. |
Github GHSA |
GHSA-2cm5-f78c-h2c8 | Missing permission checks in Jenkins Distributed Fork Plugin |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-09-16T19:31:32.320Z
Reserved: 2016-12-01T00:00:00
Link: CVE-2017-2652
No data.
Status : Modified
Published: 2018-07-27T20:29:00.530
Modified: 2024-11-21T03:23:54.880
Link: CVE-2017-2652
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA