PT-2022-26912 · Compuware+1 · Jenkins Compuware Topaz For Total Test Plugin+1
Published
2022-10-19
·
Updated
2025-05-08
·
CVE-2022-43428
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Compuware Topaz for Total Test Plugin versions 2.4.8 and earlier
Description
The issue allows attackers who can control agent processes to obtain the values of Java system properties from the Jenkins controller process due to an agent/controller message that does not limit where it can be executed. These vulnerabilities are only exploitable in certain versions of Jenkins.
Recommendations
For Jenkins Compuware Topaz for Total Test Plugin versions 2.4.8 and earlier, update the plugin to a version later than 2.4.8 to resolve the issue.
For Jenkins 2.318 and earlier, LTS 2.303.2 and earlier, upgrade to a newer version, such as Jenkins LTS 2.303.3 or later, following the LTS upgrade guide.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Compuware Topaz For Total Test Plugin