CRITICAL
jenkins: Users with agent related permissions in EC2 Plugin are able to run arbitrary shell commands on master node
Published Jan 24, 2018
9.9
CRITICALCVSS 3.0
EPSS 1.59%
Description
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only granted to administrators.
Affected products
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2017-1000502 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1539525 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5612 Advisory
- https://github.com/advisories/GHSA-wp79-cpv2-9g7m Advisory
- https://jenkins.io/security/advisory/2017-12-06/ x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000502
- https://www.cve.org/CVERecord?id=CVE-2017-1000502
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2017-1000502 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1539525 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5612 | Advisory | |
| https://github.com/advisories/GHSA-wp79-cpv2-9g7m | Advisory | |
| https://jenkins.io/security/advisory/2017-12-06/ | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000502 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000502 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 24, 2018
Updated Sep 16, 2024
Reserved Jan 24, 2018
Link CVE-2017-1000502
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-5612 GHSA-WP79-CPV2-9G7M Assigner mitre
Published Jan 24, 2018
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2022-5612