Vulnerability Details CVE-2022-30951
Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.4%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2022-30951
-
cpe:2.3:a:jenkins:wmi_windows_agents:1.0
-
cpe:2.3:a:jenkins:wmi_windows_agents:1.1
-
cpe:2.3:a:jenkins:wmi_windows_agents:1.2
-
cpe:2.3:a:jenkins:wmi_windows_agents:1.3
-
cpe:2.3:a:jenkins:wmi_windows_agents:1.3.1
-
cpe:2.3:a:jenkins:wmi_windows_agents:1.4
-
cpe:2.3:a:jenkins:wmi_windows_agents:1.5
-
cpe:2.3:a:jenkins:wmi_windows_agents:1.6
-
cpe:2.3:a:jenkins:wmi_windows_agents:1.7
-
cpe:2.3:a:jenkins:wmi_windows_agents:1.8