PT-2022-20405 · Jenkins · Jenkins Wmi Windows Agents Plugin+1
Kalle Niemitalo
·
Published
2022-05-17
·
Updated
2023-11-03
·
CVE-2022-30950
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins WMI Windows Agents Plugin versions 1.8 and earlier
Description
The issue is related to a buffer overflow vulnerability in the Windows Remote Command library included in the Jenkins WMI Windows Agents Plugin. This vulnerability may allow users who can connect to a named pipe to execute commands on the Windows agent machine. The library provides a remote command execution capability used by Jenkins to check for and install Java if it's not available. Additionally, the library lacks access control, potentially allowing users to start processes even if they are not permitted to log in.
Recommendations
For Jenkins WMI Windows Agents Plugin versions 1.8 and earlier, update to version 1.8.1 or later, which no longer includes the vulnerable Windows Remote Command library. Note that version 1.8.1 requires a Java runtime to be available on agent machines and does not install a JDK automatically if it's missing.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Wmi Windows Agents Plugin