Description
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.
Remediation
References
http://www.securityfocus.com/bid/96980
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2021-21624 Vulnerability in maven package org.jenkins-ci.plugins:role-strategy
CVE-2020-7701 Vulnerability in npm package madlib-object-utils
CVE-2018-19056 Vulnerability in npm package editor.md
CVE-2018-20676 Vulnerability in maven package org.webjars:bootstrap
CVE-2023-27495 Vulnerability in npm package @fastify/csrf-protection