Denial of Access in Jenkins Compuware ISPW Operations Plugin by Jenkins
CVE-2022-36899

8.2HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
27 July 2022

Summary

The Jenkins Compuware ISPW Operations Plugin version 1.0.8 and earlier contains a security flaw that fails to restrict the execution of controller/agent messages solely to authorized agents. This oversight allows an attacker who can control the agent processes to access sensitive Java system properties, potentially compromising the security integrity of affected systems. It is crucial for users to update their plugins to mitigate risks associated with this vulnerability. For further information, refer to the official Jenkins security advisory.

Affected Version(s)

Jenkins Compuware ISPW Operations Plugin <= 1.0.8

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.