PT-2022-26906 · Compuware+1 · Jenkins Compuware Topaz Utilities Plugin+1

CVE-2022-43422

·

Published

2022-10-19

·

Updated

2025-05-08

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Compuware Topaz Utilities Plugin versions 1.0.8 and earlier
Description The issue allows attackers who can control agent processes to obtain the values of Java system properties from the Jenkins controller process due to an agent/controller message that does not limit where it can be executed. This can be exploited in Jenkins versions 2.318 and earlier, and LTS versions 2.303.2 and earlier.
Recommendations For Jenkins Compuware Topaz Utilities Plugin versions 1.0.8 and earlier, update to version 1.0.9 or later, which restricts execution of the agent/controller message to agents. For Jenkins versions 2.318 and earlier, and LTS versions 2.303.2 and earlier, consider upgrading to a newer version to mitigate the risk of exploitation.

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-43422
GHSA-2X49-WJ38-78Q9

Affected Products

Jenkins
Jenkins Compuware Topaz Utilities Plugin