PT-2022-26912 · Compuware+1 · Jenkins Compuware Topaz For Total Test Plugin+1

Published

2022-10-19

·

Updated

2025-05-08

·

CVE-2022-43428

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Compuware Topaz for Total Test Plugin versions 2.4.8 and earlier
Description The issue allows attackers who can control agent processes to obtain the values of Java system properties from the Jenkins controller process due to an agent/controller message that does not limit where it can be executed. These vulnerabilities are only exploitable in certain versions of Jenkins.
Recommendations For Jenkins Compuware Topaz for Total Test Plugin versions 2.4.8 and earlier, update the plugin to a version later than 2.4.8 to resolve the issue. For Jenkins 2.318 and earlier, LTS 2.303.2 and earlier, upgrade to a newer version, such as Jenkins LTS 2.303.3 or later, following the LTS upgrade guide.

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2022-43428
GHSA-XP3R-9WX8-Q2MM

Affected Products

Jenkins
Jenkins Compuware Topaz For Total Test Plugin