PT-2022-26913 · Compuware+1 · Jenkins Compuware Topaz For Total Test Plugin+1
Published
2022-10-19
·
Updated
2023-11-03
·
CVE-2022-43429
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Compuware Topaz for Total Test Plugin versions 2.4.8 and earlier
Description
The issue allows attackers who can control agent processes to read arbitrary files on the Jenkins controller file system due to an agent/controller message that does not limit where it can be executed.
Recommendations
For versions 2.4.8 and earlier, update to a version that contains a fix for this issue to prevent attackers from reading arbitrary files on the Jenkins controller file system.
Fix
Improper Access Control
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Compuware Topaz For Total Test Plugin