CVE-2022-43423
MEDIUMJenkins Compuware Source Code Download for Endevor, PDS, and ISPW P...
Title source: llmDescription
Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.
Scores
CVSS v3
5.3
EPSS
0.0137
EPSS Percentile
80.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-610
Status
published
Products (2)
com.compuware.jenkins/compuware-scm-downloader
0 - 2.0.13Maven
jenkins/compuware_source_code_download_for_endevor\,_pds\,_and_ispw
< 2.0.13
Published
Oct 19, 2022
Tracked Since
Feb 18, 2026