Lucene search

K
cvelistJenkinsCVELIST:CVE-2022-43423
HistoryOct 19, 2022 - 12:00 a.m.

CVE-2022-43423

2022-10-1900:00:00
jenkins
www.cve.org
1
jenkins
compuware
source code download
plugin
vulnerability
java system properties

0.001 Low

EPSS

Percentile

33.5%

Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

CNA Affected

[
  {
    "product": "Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "2.0.12",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

33.5%

Related for CVELIST:CVE-2022-43423