A data modification vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgent.java that allows attackers with Overall/Read permission to attach a public IP address to an Azure VM agent.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-4473 A data modification vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgent.java that allows attackers with Overall/Read permission to attach a public IP address to an Azure VM agent.
Github GHSA Github GHSA GHSA-m33c-cjjj-2mg4 Missing permission check in Azure VM Agents Plugin allowed modifying VM configuration
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-08-05T03:07:16.789Z

Reserved: 2019-03-08T00:00:00

Link: CVE-2019-1003036

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-03-08T21:29:00.560

Modified: 2024-11-21T04:17:47.047

Link: CVE-2019-1003036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.