Description
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.
Remediation
References
http://www.securityfocus.com/bid/96980
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2022-21126 Vulnerability in maven package com.github.samtools:htsjdk
CVE-2020-11113 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2018-25031 Vulnerability in maven package org.webjars.npm:swagger-ui-dist
CVE-2021-23342 Vulnerability in npm package docsify
CVE-2016-5725 Vulnerability in maven package com.jcraft:jsch