GHSA-2cm5-f78c-h2c8
GitHub Security Advisory
Missing permission checks in Jenkins Distributed Fork Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.
Affected Packages
Maven
org.jenkins-ci.plugins:distfork
Affected versions:
0
(fixed in 1.6.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.