Description
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.
Remediation
References
https://jenkins.io/security/advisory/2017-03-20/
http://www.securityfocus.com/bid/96980
Related Vulnerabilities
CVE-2021-40369 Vulnerability in maven package org.apache.jspwiki:jspwiki-main
CVE-2020-13920 Vulnerability in maven package org.apache.activemq:activemq-broker
CVE-2021-21162 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-3637 Vulnerability in maven package org.keycloak:keycloak-model-infinispan
CVE-2023-37955 Vulnerability in maven package org.jenkins-ci.plugins:test-results-aggregator