CVE-2022-43428
MEDIUMJenkins Compuware Topaz for Total Test Plugin <2.4.8 - Info Disclosure
Title source: llmDescription
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.
Scores
CVSS v3
5.3
EPSS
0.0137
EPSS Percentile
80.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-610
Status
published
Products (2)
com.compuware.jenkins/compuware-topaz-for-total-test
0 - 2.4.9Maven
jenkins/compuware_topaz_for_total_test
< 2.4.8
Published
Oct 19, 2022
Tracked Since
Feb 18, 2026