PT-2022-20405 · Jenkins · Jenkins Wmi Windows Agents Plugin+1

Kalle Niemitalo

·

Published

2022-05-17

·

Updated

2023-11-03

·

CVE-2022-30950

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins WMI Windows Agents Plugin versions 1.8 and earlier
Description The issue is related to a buffer overflow vulnerability in the Windows Remote Command library included in the Jenkins WMI Windows Agents Plugin. This vulnerability may allow users who can connect to a named pipe to execute commands on the Windows agent machine. The library provides a remote command execution capability used by Jenkins to check for and install Java if it's not available. Additionally, the library lacks access control, potentially allowing users to start processes even if they are not permitted to log in.
Recommendations For Jenkins WMI Windows Agents Plugin versions 1.8 and earlier, update to version 1.8.1 or later, which no longer includes the vulnerable Windows Remote Command library. Note that version 1.8.1 requires a Java runtime to be available on agent machines and does not install a JDK automatically if it's missing.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-30950
GHSA-XHW3-WMX2-76WF

Affected Products

Jenkins
Jenkins Wmi Windows Agents Plugin