High severity8.8NVD Advisory· Published May 17, 2022· Updated Jun 17, 2026
CVE-2022-30951
CVE-2022-30951
Description
Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:windows-slavesMaven | < 1.8.1 | 1.8.1 |
Affected products
2- Jenkins project/Jenkins WMI Windows Agents Pluginv5Range: unspecified
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2022/05/17/8nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-p566-wpxx-574mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-30951ghsaADVISORY
- www.jenkins.io/security/advisory/2022-05-17/nvdVendor AdvisoryWEB
- github.com/jenkinsci/windows-slaves-plugin/commit/4638cf0e56caf839eadfdf0fab545abd2a9ac65eghsaWEB
News mentions
1- Jenkins Security Advisory 2022-05-17Jenkins Security Advisories · May 17, 2022