← Back

CVE-2022-43424

nvd nist
Published: Oct 19, 2022Modified: May 8, 2025

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

Affected (1)

1 product
Compuware Xpediter Code Coverage
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 1.0.8
Running on/withPlatform Versions
Jenkins
Jenkins
Up to 2.318
Jenkins
Jenkins
Up to 2.303.2

References (4)

Source: jenkinsci-cert@googlegroups.com
Mailing ListThird Party Advisory
Source: jenkinsci-cert@googlegroups.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.