CVE-2022-43429
HIGHJenkins Compuware Topaz for Total Test Plugin <2.4.8 - Info Disclosure
Title source: llmDescription
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.
References (2)
Core 2
Core References
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/10/19/3
Scores
CVSS v3
7.5
EPSS
0.0066
EPSS Percentile
71.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Products (2)
com.compuware.jenkins/compuware-topaz-for-total-test
0Maven
jenkins/compuware_topaz_for_total_test
< 2.4.8
Published
Oct 19, 2022
Tracked Since
Feb 18, 2026