CVE-2017-2652

Improper Authentication in maven/org.jenkins-ci.plugins/distfork

Identifiers

GHSA-2cm5-f78c-h2c8, CVE-2017-2652

Package Slug

maven/org.jenkins-ci.plugins/distfork

Vulnerability

Improper Authentication

Description

It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.

Affected Versions

All versions up to 1.5.0

Solution

Upgrade to version 1.6.0 or above.

Last Modified

2024-01-31

source