Jenkins Compuware Source Code Plugin Vulnerability Exposes Sensitive Java Properties
CVE-2022-43423
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 19 October 2022
What is CVE-2022-43423?
The Jenkins Compuware Source Code Download plugin prior to version 2.0.13 is susceptible to an improper access control vulnerability. This issue arises from an unrestricted execution of agent/controller messages. Consequently, attackers with control over agent processes might exploit this flaw to access sensitive Java system properties from the Jenkins controller process. This vulnerability could lead to exposure of critical configuration details, enhancing the risk of further attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin <= 2.0.12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved