Description
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.
Remediation
References
http://www.securityfocus.com/bid/96980
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2017-2599 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-8137 Vulnerability in npm package uppy
CVE-2019-0191 Vulnerability in maven package org.apache.karaf.kar:org.apache.karaf.kar.core
CVE-2022-4725 Vulnerability in maven package com.amazonaws:aws-android-sdk-core
CVE-2019-1003029 Vulnerability in maven package org.jenkins-ci.plugins:script-security