#VU17920 Improper access control in Azure VM Agents
Published: March 7, 2019 / Updated: March 7, 2019
Azure VM Agents
Jenkins
Description
The vulnerability allows a remote attacker to change VM configuration and gain access to sensitive information.
The vulnerability exists due to missing permissions check in an HTTP endpoint. A remote attacker with Overall/Read access can attach a public IP address to an Azure VM in Azure VM Agents Plugin and making a virtual machine publicly accessible.
Note, this vulnerability can be exploited via CSRF attack vector.