Agent/Controller Message Execution Flaw in Jenkins Compuware Topaz for Total Test Plugin
CVE-2022-43428
5.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 19 October 2022
What is CVE-2022-43428?
The Jenkins Compuware Topaz for Total Test Plugin incorporates a vulnerability where an agent/controller message lacks restrictions on its execution context. This imperfection permits attackers with control over agent processes to access sensitive Java system properties from the Jenkins controller process, increasing the risk of unauthorized information disclosure and potential subsequent attacks.
Affected Version(s)
Jenkins Compuware Topaz for Total Test Plugin <= 2.4.8