PT-2022-26906 · Compuware+1 · Jenkins Compuware Topaz Utilities Plugin+1
CVE-2022-43422
·
Published
2022-10-19
·
Updated
2025-05-08
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Compuware Topaz Utilities Plugin versions 1.0.8 and earlier
Description
The issue allows attackers who can control agent processes to obtain the values of Java system properties from the Jenkins controller process due to an agent/controller message that does not limit where it can be executed. This can be exploited in Jenkins versions 2.318 and earlier, and LTS versions 2.303.2 and earlier.
Recommendations
For Jenkins Compuware Topaz Utilities Plugin versions 1.0.8 and earlier, update to version 1.0.9 or later, which restricts execution of the agent/controller message to agents.
For Jenkins versions 2.318 and earlier, and LTS versions 2.303.2 and earlier, consider upgrading to a newer version to mitigate the risk of exploitation.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Compuware Topaz Utilities Plugin