Denial of Access in Jenkins Compuware ISPW Operations Plugin by Jenkins
CVE-2022-36899
8.2HIGH
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 27 July 2022
Summary
The Jenkins Compuware ISPW Operations Plugin version 1.0.8 and earlier contains a security flaw that fails to restrict the execution of controller/agent messages solely to authorized agents. This oversight allows an attacker who can control the agent processes to access sensitive Java system properties, potentially compromising the security integrity of affected systems. It is crucial for users to update their plugins to mitigate risks associated with this vulnerability. For further information, refer to the official Jenkins security advisory.
Affected Version(s)
Jenkins Compuware ISPW Operations Plugin <= 1.0.8
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved