CVE-2022-30951

HIGH

Jenkins WMI Windows Agents Plugin <1.8 - RCE

Title source: llm
STIX 2.1

Description

Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/05/17/8

Scores

CVSS v3 8.8
EPSS 0.0014
EPSS Percentile 34.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (2)
jenkins/wmi_windows_agents < 1.8.1
org.jenkins-ci.plugins/windows-slaves 0 - 1.8.1Maven
Published May 17, 2022
Tracked Since Feb 18, 2026