#VU17919 Improper access control in Azure VM Agents
Published: March 7, 2019 / Updated: March 7, 2019
Azure VM Agents
Jenkins
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to missing permissions check in a form validation method in Azure VM Agents Plugin. A remote attacker with Overall/Read access to verify a submitted configuration can obtain sensitive information about the Azure account and configuration.
Note, this vulnerability can be exploited via CSRF attack vector.