Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-43427
HistoryOct 19, 2022 - 4:15 p.m.

Design/Logic Flaw

2022-10-1916:15:00
PRIOn knowledge base
www.prio-n.com
1
jenkins
compuware
permission
http endpoints
credentials
enumeration
nvd

4.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.0%

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CPENameOperatorVersion
compuware_topaz_for_total_testlt2.4.8

4.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.0%

Related for PRION:CVE-2022-43427