CVE-2022-43423: Medium severity Jenkins Compuware Source Code Download For Endevor\, Pds\, And Ispw Jenkins vulnerability
BMC Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controller message that does not limit where it can be executed.
It allows attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.
This vulnerability is only exploitable in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. See the LTS upgrade guide.
BMC Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.13 restricts execution of the agent/controller message to agents.
Other sources
Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.compuware.jenkins:compuware-scm-downloaderto a version that resolves this vulnerability.Fixed in 2.0.13 - Upgrade
Upgrade
BMC Compuware Source Code Download for Endevor, PDS, and ISPW Pluginto a version that resolves this vulnerability.Fixed in 2.0.13 - Upgrade
Upgrade
Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Pluginto a version that resolves this vulnerability.Fixed in 2.0.13 - Configuration
Ensure the agent/controller message is restricted to agents (as implemented in plugin 2.0.13) so it cannot be executed where it allows access to Java system properties from the Jenkins controller process.
BMC Compuware Source Code Download for Endevor, PDS, and ISPW Plugin agent/controller message handling Execution scope of agent/controller message = restricted to agents
Event History
Frequently Asked Questions
What is the vulnerability ID of this Jenkins vulnerability?
The vulnerability ID of this Jenkins vulnerability is CVE-2022-43423.
What is the severity of CVE-2022-43423?
The severity of CVE-2022-43423 is medium with a CVSS score of 5.3.
What is the affected software of CVE-2022-43423?
The affected software of CVE-2022-43423 is Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin version 2.0.12 and earlier.
How can attackers exploit CVE-2022-43423?
Attackers able to control agent processes can exploit CVE-2022-43423 to obtain the values of Java system properties from the Jenkins controller.
Are the Jenkins LTS versions vulnerable to CVE-2022-43423?
No, the Jenkins LTS versions are not vulnerable to CVE-2022-43423.