SB2019030706 - Multiple vulnerabilities in Jenkins Azure VM Agents plugin
Published: March 7, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Improper access control (CVE-ID: N/A)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to missing permissions check in a form validation method in Azure VM Agents Plugin. A remote attacker with Overall/Read access to verify a submitted configuration can obtain sensitive information about the Azure account and configuration.
Note, this vulnerability can be exploited via CSRF attack vector.
2) Improper access control (CVE-ID: N/A)
The vulnerability allows a remote attacker to change VM configuration and gain access to sensitive information.
The vulnerability exists due to missing permissions check in an HTTP endpoint. A remote attacker with Overall/Read access can attach a public IP address to an Azure VM in Azure VM Agents Plugin and making a virtual machine publicly accessible.
Note, this vulnerability can be exploited via CSRF attack vector.
3) Improper access control (CVE-ID: N/A)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to missing permissions check when displaying a list of valid credentials IDs. A remote attacker with Overall/Read access can obtain a list of credentials identifiers.
Remediation
Install update from vendor's website.