Description
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.
Remediation
References
http://www.securityfocus.com/bid/96980
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2018-16131 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.12
CVE-2022-39266 Vulnerability in npm package isolated-vm
CVE-2018-8030 Vulnerability in maven package org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol
CVE-2018-14721 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-2118 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-githubnotify-step