VDB

CISA-2022-43428

CISA-2022-43428 PUBLISHED CVSS 5.3 MEDIUM

Reported by jenkins · Published October 19, 2022

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

Risk Scores

CVSS 3.1
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
Jenkins projectJenkins Compuware Topaz for Total Test Pluginunspecified, next of 2.4.8
Jenkins projectJenkins Compuware Topaz for Total Test Pluginunspecified, *, *

Timeline

  • Oct 19, 2022 CVE Published
  • May 8, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›