Jenkins Compuware Source Code Plugin Vulnerability Exposes Sensitive Java Properties
CVE-2022-43423
5.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 19 October 2022
What is CVE-2022-43423?
The Jenkins Compuware Source Code Download plugin prior to version 2.0.13 is susceptible to an improper access control vulnerability. This issue arises from an unrestricted execution of agent/controller messages. Consequently, attackers with control over agent processes might exploit this flaw to access sensitive Java system properties from the Jenkins controller process. This vulnerability could lead to exposure of critical configuration details, enhancing the risk of further attacks.
Affected Version(s)
Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin <= 2.0.12