CVE-2022-43427: Medium severity Jenkins Compuware Topaz For Total Test Wordpress vulnerability
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.compuware.jenkins:compuware-topaz-for-total-testto a version that resolves this vulnerability.Fixed in 2.4.9
Event History
Frequently Asked Questions
What is CVE-2022-43427?
CVE-2022-43427 is a vulnerability in Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier that allows attackers to enumerate credentials stored in Jenkins.
What is the severity of CVE-2022-43427?
The severity of CVE-2022-43427 is medium with a CVSS score of 4.3.
How can an attacker exploit CVE-2022-43427?
An attacker with Overall/Read permission can exploit CVE-2022-43427 to enumerate credentials IDs of credentials stored in Jenkins.
What is the affected software for CVE-2022-43427?
The affected software for CVE-2022-43427 is Jenkins Compuware Topaz for Total Test Plugin version 2.4.8 and earlier.
Is there a fix for CVE-2022-43427?
Yes, Jenkins has released a security advisory with fixes for CVE-2022-43427. It is recommended to update to a version that includes the fix.