Agent/Controller Message Execution Flaw in Jenkins Compuware Topaz for Total Test Plugin
CVE-2022-43428
5.3MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 19 October 2022
Summary
The Jenkins Compuware Topaz for Total Test Plugin incorporates a vulnerability where an agent/controller message lacks restrictions on its execution context. This imperfection permits attackers with control over agent processes to access sensitive Java system properties from the Jenkins controller process, increasing the risk of unauthorized information disclosure and potential subsequent attacks.
Affected Version(s)
Jenkins Compuware Topaz for Total Test Plugin <= 2.4.8
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved