PT-2022-20406 · Jenkins · Jenkins Wmi Windows Agents Plugin+1

Kalle Niemitalo

·

Published

2022-05-17

·

Updated

2023-11-03

·

CVE-2022-30951

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins WMI Windows Agents Plugin versions 1.8 and earlier
Description The Jenkins WMI Windows Agents Plugin includes the Windows Remote Command library, which does not implement access control. This potentially allows users to start processes even if they are not allowed to log in. The library provides a general-purpose remote command execution capability, which may allow users to execute commands on the Windows agent machine due to a buffer overflow vulnerability.
Recommendations For Jenkins WMI Windows Agents Plugin versions 1.8 and earlier, update to version 1.8.1 or later, which no longer includes the Windows Remote Command library. Ensure a Java runtime is available on agent machines, as version 1.8.1 does not install a JDK automatically.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-30951
GHSA-P566-WPXX-574M

Affected Products

Jenkins
Jenkins Wmi Windows Agents Plugin