CVE-2022-43424
MEDIUMJenkins Compuware Xpediter Code Coverage Plugin <1.0.7 - Info Discl...
Title source: llmDescription
Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.
Scores
CVSS v3
5.3
EPSS
0.0137
EPSS Percentile
80.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-693
Status
published
Affected Products (2)
jenkins/compuware_xpediter_code_coverage
< 1.0.8
com.compuware.jenkins/compuware-xpediter-code-coverage
< 1.0.8Maven
Timeline
Published
Oct 19, 2022
Tracked Since
Feb 18, 2026