Denial of Access in Jenkins Compuware ISPW Operations Plugin by Jenkins
CVE-2022-36899
8.2HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 27 July 2022
What is CVE-2022-36899?
The Jenkins Compuware ISPW Operations Plugin version 1.0.8 and earlier contains a security flaw that fails to restrict the execution of controller/agent messages solely to authorized agents. This oversight allows an attacker who can control the agent processes to access sensitive Java system properties, potentially compromising the security integrity of affected systems. It is crucial for users to update their plugins to mitigate risks associated with this vulnerability. For further information, refer to the official Jenkins security advisory.
Affected Version(s)
Jenkins Compuware ISPW Operations Plugin <= 1.0.8