Description
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.
Remediation
References
http://www.securityfocus.com/bid/96980
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2019-19771 Vulnerability in npm package bip30
CVE-2022-41404 Vulnerability in maven package org.ini4j:ini4j
CVE-2023-34616 Vulnerability in maven package com.progsbase.libraries:json
CVE-2023-47321 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2014-0219 Vulnerability in maven package org.apache.karaf:org.apache.karaf.main