V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2017-1000502
DEB
Critical

Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell command…

CVSS
9.9
Critical
EPSS
0.02
p73
Published
2017-01-01
Updated
2017-01-01
Description

Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only granted to administrators.

Tags · CWE
CWE-732
CWE-78
CAPEC-1
CAPEC-6
CAPEC-15
CAPEC-17
CAPEC-43
CAPEC-60
CAPEC-61
CAPEC-62
CAPEC-88
CAPEC-108
CAPEC-122
CAPEC-127
CAPEC-180
CAPEC-206
CAPEC-234
CAPEC-642
Affected products
Ec2 ≤ 1.37
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.016 · p73
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-127 · CWE-732
└ via CAPEC-60 · CWE-732
└ via CAPEC-642 · CWE-732
└ via CAPEC-122 · CWE-732
└ via CAPEC-60 · CWE-732
└ via CAPEC-206 · CWE-732
└ via CAPEC-642 · CWE-732
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
jenkinsTracked
ec2*Tracked
Source databases
DEB
CVE