PT-2022-26913 · Compuware+1 · Jenkins Compuware Topaz For Total Test Plugin+1

Published

2022-10-19

·

Updated

2023-11-03

·

CVE-2022-43429

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Compuware Topaz for Total Test Plugin versions 2.4.8 and earlier
Description The issue allows attackers who can control agent processes to read arbitrary files on the Jenkins controller file system due to an agent/controller message that does not limit where it can be executed.
Recommendations For versions 2.4.8 and earlier, update to a version that contains a fix for this issue to prevent attackers from reading arbitrary files on the Jenkins controller file system.

Fix

Improper Access Control

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-43429
GHSA-7FVJ-G3WP-29G8

Affected Products

Jenkins
Jenkins Compuware Topaz For Total Test Plugin