Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library which has a buffer overflow vulnerability that may allow users able to connect to a named pipe to execute commands on the Windows agent machine.
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
Link | Tags |
---|---|
https://www.jenkins.io/security/advisory/2022-05-17/#SECURITY-2604 | vendor advisory |
http://www.openwall.com/lists/oss-security/2022/05/17/8 | third party advisory mailing list |