Lucene search

K
cvelistJenkinsCVELIST:CVE-2022-43424
HistoryOct 19, 2022 - 12:00 a.m.

CVE-2022-43424

2022-10-1900:00:00
jenkins
www.cve.org
jenkins
compuware xpediter
code coverage plugin
security vulnerability
java system properties

0.001 Low

EPSS

Percentile

33.5%

Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

CNA Affected

[
  {
    "product": "Jenkins Compuware Xpediter Code Coverage Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "1.0.7",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

33.5%

Related for CVELIST:CVE-2022-43424