QID 997312
Date Published: 2024-02-20
QID 997312: Java (Maven) Security Update for org.jenkins-ci.plugins:ec2 (GHSA-wp79-cpv2-9g7m)
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only granted to administrators.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-wp79-cpv2-9g7m for updates and patch information.
Vendor References
- GHSA-wp79-cpv2-9g7m -
github.com/advisories/GHSA-wp79-cpv2-9g7m
CVEs related to QID 997312
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wp79-cpv2-9g7m | org.jenkins-ci.plugins:ec2 |
|