CVE-2022-43428: High severity Jenkins Compuware Topaz For Total Test Jenkins vulnerability
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.compuware.jenkins:compuware-topaz-for-total-testto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade
Jenkins Compuware Topaz for Total Test Pluginto a version that resolves this vulnerability.Fixed in 2.4.8 and earlier - Compensating control
If running a vulnerable Jenkins version, mitigate until patched by restricting/limiting where agent/controller message execution can occur so attackers cannot control agent processes to read Java system properties from the Jenkins controller process.
Event History
Frequently Asked Questions
What is CVE-2022-43428?
CVE-2022-43428 is a vulnerability in Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier that allows attackers to obtain the values of Java system properties from the Jenkins controller process.
What software versions are affected by CVE-2022-43428?
Jenkins Compuware Topaz for Total Test Plugin version 2.4.8 and earlier are affected by CVE-2022-43428.
What is the severity of CVE-2022-43428?
CVE-2022-43428 has a severity rating of 5.3, which is considered medium.
How can an attacker exploit CVE-2022-43428?
An attacker who can control agent processes can exploit CVE-2022-43428 to obtain the values of Java system properties from the Jenkins controller process.
Is Jenkins Jenkins version 2.303.2 vulnerable to CVE-2022-43428?
No, Jenkins Jenkins version 2.303.2 is not vulnerable to CVE-2022-43428.