Loading HuntDB...

GHSA-2cm5-f78c-h2c8

GitHub Security Advisory

Missing permission checks in Jenkins Distributed Fork Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.

Affected Packages

Maven org.jenkins-ci.plugins:distfork
Affected versions: 0 (fixed in 1.6.0)

Related CVEs

Key Information

GHSA ID
GHSA-2cm5-f78c-h2c8
Published
May 13, 2022 1:36 AM
Last Modified
January 30, 2024 10:19 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:distfork
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.