SB2019030706 - Multiple vulnerabilities in Jenkins Azure VM Agents plugin



SB2019030706 - Multiple vulnerabilities in Jenkins Azure VM Agents plugin

Published: March 7, 2019

Security Bulletin ID SB2019030706
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Improper access control (CVE-ID: N/A)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to missing permissions check in a form validation method in Azure VM Agents Plugin. A remote attacker with Overall/Read access to verify a submitted configuration can obtain sensitive information about the Azure account and configuration.

Note, this vulnerability can be exploited via CSRF attack vector.


2) Improper access control (CVE-ID: N/A)

The vulnerability allows a remote attacker to change VM configuration and gain access to sensitive information.

The vulnerability exists due to missing permissions check in an HTTP endpoint. A remote attacker with Overall/Read access can attach a public IP address to an Azure VM in Azure VM Agents Plugin and making a virtual machine publicly accessible.

Note, this vulnerability can be exploited via CSRF attack vector.


3) Improper access control (CVE-ID: N/A)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to missing permissions check when displaying a list of valid credentials IDs. A remote attacker with Overall/Read access can obtain a list of credentials identifiers.


Remediation

Install update from vendor's website.