CVE-2022-43430: XEE
Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
This allows attackers able to control the input files for the 'Topaz for Total Test - Execute Total Test scenarios' build step to have Jenkins parse a crafted XML document that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
Other sources
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.compuware.jenkins:compuware-topaz-for-total-testto a version that resolves this vulnerability.Fixed in 2.4.9
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-43430.
What is the title of this vulnerability?
The title of this vulnerability is Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
What is the severity of CVE-2022-43430?
The severity of CVE-2022-43430 is high with a CVSS score of 7.5.
What software versions are affected by CVE-2022-43430?
Jenkins Compuware Topaz for Total Test Plugin versions 2.4.8 and earlier are affected by CVE-2022-43430.
How can I fix CVE-2022-43430?
To fix CVE-2022-43430, you should update Jenkins Compuware Topaz for Total Test Plugin to a version beyond 2.4.8.