CVE-2022-43429

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:jenkins:compuware_topaz_for_total_test:*:*:*:*:*:wordpress:*:*
OR cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*

Information

Published : 2022-10-19 09:15

Updated : 2022-10-21 19:24


NVD link : CVE-2022-43429

Mitre link : CVE-2022-43429


JSON object : View

CWE
CWE-693

Protection Mechanism Failure

Advertisement

dedicated server usa

Products Affected

jenkins

  • compuware_topaz_for_total_test
  • jenkins