Lucene search

K
cvelistJenkinsCVELIST:CVE-2022-43428
HistoryOct 19, 2022 - 12:00 a.m.

CVE-2022-43428

2022-10-1900:00:00
jenkins
www.cve.org
1
jenkins
compuware
total test plugin
vulnerability
java system properties

0.001 Low

EPSS

Percentile

33.5%

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

CNA Affected

[
  {
    "product": "Jenkins Compuware Topaz for Total Test Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "2.4.8",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 2.4.8",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

33.5%

Related for CVELIST:CVE-2022-43428