First published: Wed Jul 27 2022(Updated: )
Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Compuware Ispw Operations | <1.0.9 | |
Jenkins Jenkins | <=2.303.2 | |
Jenkins Jenkins | <=2.318 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36899 is a vulnerability in Jenkins Compuware ISPW Operations Plugin that allows attackers to retrieve Java system properties by executing controller/agent messages.
CVE-2022-36899 has a severity rating of 8.2, which is considered high.
Jenkins Compuware ISPW Operations Plugin versions 1.0.8 and earlier are affected by CVE-2022-36899.
An attacker with control over agent processes can exploit CVE-2022-36899 to retrieve Java system properties.
No, Jenkins Jenkins LTS versions up to 2.303.2 are not vulnerable to CVE-2022-36899.