Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.
2022-07-27T15:15:09.723
2024-11-21T07:14:01.840
Modified
CVSSv3.1: 8.2 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | jenkins | compuware_ispw_operations | < 1.0.9 | Yes |
| Application | jenkins | jenkins | ≤ 2.303.2 | No |
| Application | jenkins | jenkins | ≤ 2.318 | No |