CVE-2017-1000502
published 2018-01-24CVE-2017-1000502: Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node…
PriorityP350high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.59%
72.9th percentile
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only granted to administrators.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | agent-related_permissions_in_ec2_plugin | — | — |
| jenkins | ec2 | <= 1.37 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Arbitrary shell command execution in Jenkins EC2 Plugin
osv·2022-05-14
CVE-2017-1000502 [HIGH] Arbitrary shell command execution in Jenkins EC2 Plugin
Arbitrary shell command execution in Jenkins EC2 Plugin
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only granted to administrators.
GHSA
Arbitrary shell command execution in Jenkins EC2 Plugin
ghsa·2022-05-14
CVE-2017-1000502 [HIGH] CWE-78 Arbitrary shell command execution in Jenkins EC2 Plugin
Arbitrary shell command execution in Jenkins EC2 Plugin
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only granted to administrators.
Red Hat
jenkins: Users with agent related permissions in EC2 Plugin are able to run arbitrary shell commands on master node
vendor_redhat·2018-01-24·CVSS 8.8
CVE-2017-1000502 [HIGH] CWE-732 jenkins: Users with agent related permissions in EC2 Plugin are able to run arbitrary shell commands on master node
jenkins: Users with agent related permissions in EC2 Plugin are able to run arbitrary shell commands on master node
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only granted to administrators.
Package: jenkins (Red Hat OpenShift Enterprise 3) - Not affected
Jenkins
Jenkins Security Advisory 2017-12-06
vendor_jenkins·2017-12-06·CVSS 8.8
CVE-2017-1000502 [HIGH] Jenkins Security Advisory 2017-12-06
Title: Jenkins Security Advisory 2017-12-06
Jenkins Security Advisory 2017-12-06
This advisory announces a vulnerability in this Jenkins plugin:
EC2
Description
Arbitrary shell command execution on controller by users with Agent-related permissions in EC2 Plugin
SECURITY-643 / CVE-2017-1000502
Users with permission to create or configure agents in Jenkins could configure an EC2 agent to run arbitrary shell commands on the Jenkins controller whenever the agent was supposed to be launched.
Configuration of these agents now requires the Run Scripts permission typically only granted to administrators.
Severity
SECURITY-643: high
Affected versions
EC2 Plugin up to and including 1.37
Fix
EC2 Plugin should be updated to version 1.38
No detection rules found.
No public exploits indexed.
2018-01-24
Published