Unrestricted Process Execution in Jenkins WMI Windows Agents Plugin

Unrestricted Process Execution in Jenkins WMI Windows Agents Plugin

CVE-2022-30951 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in.

Learn more about our User Device Pen Test.