Missing permission check in Azure VM Agents Plugin allowed modifying VM configuration
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Dec 14, 2023
Package
Affected versions
<= 0.8.0
Patched versions
0.8.1
Description
Published by the National Vulnerability Database
Mar 8, 2019
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Dec 14, 2023
Reviewed
Dec 14, 2023
A data modification vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgent.java that allows attackers with Overall/Read permission to attach a public IP address to an Azure VM agent.
References